pypa/pip · error · InstallationError
The editable requirement
Error message
The editable requirement {req} cannot be installed when requiring hashes, because there is no single file to hash. What it means
Raised by prepare_editable_requirement (prepare.py:850) when --require-hashes mode is active and an editable requirement (-e) is being prepared. Editable installs point at a working tree/directory that changes over time, so there is no single immutable artifact to hash, making them fundamentally incompatible with hash verification.
Solutions
- Build the project into a wheel/sdist and install the artifact with a hash instead of using -e.
- Install the editable package in a separate step without --require-hashes.
- Drop --require-hashes for the environment that needs the editable install.
Example fix
# before pip install --require-hashes -e . # after python -m build --wheel pip install --require-hashes dist/MyProject-1.0-py3-none-any.whl --hash sha256:...
Defensive patterns
Strategy: validation
Validate before calling
import sys
def has_editable_in_hashed_install(argv: list[str]) -> bool:
require_hashes = '--require-hashes' in argv or any('--hash=' in a for a in argv)
has_editable = '-e' in argv or any(a.startswith('-e') for a in argv)
return require_hashes and has_editable
if __name__ == '__main__':
if has_editable_in_hashed_install(sys.argv):
print('ERROR: -e is incompatible with --require-hashes'); sys.exit(1) Type guard
def is_editable_arg(arg: str) -> bool:
return arg == '-e' or arg.startswith('-e ') or arg == '--editable' or arg.startswith('--editable=') Try / catch
from subprocess import run # Build the editable project to a wheel and install with hash instead. run(["python", "-m", "build", "--wheel", project_dir], check=True) run(["pip", "install", "--require-hashes", built_wheel], check=True)
Prevention
- Never combine -e with --require-hashes.
- Build local projects to wheels and hash them for locked installs.
- Run editable installs in a separate non-hashed environment step.
When it happens
Trigger: Calling 'pip install --require-hashes -e .' or including an editable requirement in a hashed install. The check is the very first thing prepare_editable_requirement does when self.require_hashes is True.
Common situations: Trying to lock down a project for reproducibility/security with --require-hashes while still developing an in-repo package with -e; a requirements file that combines hashes and an -e line.
Related errors
- Can't verify hashes for these file:// requirements because…
- Can't verify hashes for these requirements because we don't…
- In --require-hashes mode, all requirements must have their…
- Could not detect requirement name for
- is not a valid editable requirement. It should either be a…
AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08).
Data as JSON: /api/errors/c58bbe07b024dbc7.
Report an issue: GitHub.
Appendix: source
Thrown at src/pip/_internal/operations/prepare.py:851
download_location = join_within_directory(self.download_dir, link.filename)
if not os.path.exists(download_location):
shutil.copy(req.local_file_path, download_location)
download_path = display_path(download_location)
logger.info("Saved %s", download_path)
def prepare_editable_requirement(
self,
req: InstallRequirement,
) -> BaseDistribution:
"""Prepare an editable requirement."""
assert req.editable, "cannot prepare a non-editable req as editable"
logger.info("Obtaining %s", req)
with indent_log():
if self.require_hashes:
raise InstallationError(
f"The editable requirement {req} cannot be installed when "
"requiring hashes, because there is no single file to "
"hash."
)
req.ensure_has_source_dir(self.src_dir)
req.update_editable()
assert req.source_dir
req.download_info = direct_url_for_editable(req.unpacked_source_directory)
dist = _get_prepared_distribution(
req,
self.build_tracker,
self.build_env_installer,
self.build_isolation,
self.check_build_deps,
self.allow_editables,
)
View on GitHub (pinned to f399c37189)