pypa/pip · error · CommandError
--require-hashes and --no-require-hashes are mutually…
Error message
--require-hashes and --no-require-hashes are mutually exclusive
What it means
Raised as CommandError in RequirementCommand.get_requirements (req_command.py:431) when both --require-hashes and --no-require-hashes are set on the same invocation. Hash-checking mode enforces that every requirement (including transitive deps) carries a hash, providing tamper resistance; --no-require-hashes disables the auto-enabling of that mode when hashed requirements are seen (lines 438-441). Supplying both directly contradicts itself, so pip rejects the combination at line 430.
Solutions
- Remove one flag: use --require-hashes to enforce hashes, or --no-require-hashes to disable auto-enabling.
- Check pip.conf / PIP_* environment variables for a stray inherited --no-require-hashes or --require-hashes.
Example fix
# before pip install --require-hashes --no-require-hashes -r requirements.txt # after pip install --require-hashes -r requirements.txt
Defensive patterns
Strategy: validation
Validate before calling
# Reject contradictory hash flags before invoking pip.
def validate_hash_flags(opts):
if opts.get("require_hashes") and opts.get("no_require_hashes"):
raise ValueError("--require-hashes and --no-require-hashes are mutually exclusive")
return True Prevention
- Audit pip.conf and PIP_* env vars for inherited hash flags that conflict with CLI args.
When it happens
Trigger: `pip install --require-hashes --no-require-hashes -r requirements.txt`.
Common situations: Combining a hardened/locked install command (which sets --require-hashes) with a global pip config or env that injects --no-require-hashes; editing a script and leaving both flags in.
Related errors
- Cannot combine '--path' with '--user' or '--local'
- Cannot use '--only-dependencies' in combination with
- --pre cannot be used with --all-releases or --only-final.
- --build-constraint cannot be used with --no-build-isolation.
- Can not use any platform or abi specific options unless…
AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08).
Data as JSON: /api/errors/edcb5d7952625a5a.
Report an issue: GitHub.
Appendix: source
Thrown at src/pip/_internal/cli/req_command.py:431
if not check_requires_python(
requires_python=script_requires_python,
version_info=target_python.py_version_info,
):
raise UnsupportedPythonVersion(
f"Script {script!r} requires a different Python: "
f"{target_python.py_version} not in {script_requires_python!r}"
)
for req in script_metadata.get("dependencies", []):
req_to_add = install_req_from_req_string(
req,
isolated=options.isolated_mode,
user_supplied=True,
)
requirements.append(req_to_add)
if options.require_hashes and options.no_require_hashes:
raise CommandError(
"--require-hashes and --no-require-hashes are mutually exclusive"
)
# If any requirement has hash options, enable hash checking for all
# requirements, unless this mechanism has been explicitly disabled
# with --no-require-hashes.
if not options.no_require_hashes and any(
req.has_hash_options for req in requirements
):
options.require_hashes = True
if not (
args
or options.editables
or options.requirements
or options.dependency_groups
or options.requirements_from_scripts
):View on GitHub (pinned to f399c37189)