pypa/pip · error · InstallationError

The editable requirement

Error message

The editable requirement {req} cannot be installed when requiring hashes, because there is no single file to hash.

What it means

Raised by prepare_editable_requirement (prepare.py:850) when --require-hashes mode is active and an editable requirement (-e) is being prepared. Editable installs point at a working tree/directory that changes over time, so there is no single immutable artifact to hash, making them fundamentally incompatible with hash verification.

Solutions

  1. Build the project into a wheel/sdist and install the artifact with a hash instead of using -e.
  2. Install the editable package in a separate step without --require-hashes.
  3. Drop --require-hashes for the environment that needs the editable install.

Example fix

# before
pip install --require-hashes -e .
# after
python -m build --wheel
pip install --require-hashes dist/MyProject-1.0-py3-none-any.whl --hash sha256:...
Defensive patterns

Strategy: validation

Validate before calling

import sys

def has_editable_in_hashed_install(argv: list[str]) -> bool:
    require_hashes = '--require-hashes' in argv or any('--hash=' in a for a in argv)
    has_editable = '-e' in argv or any(a.startswith('-e') for a in argv)
    return require_hashes and has_editable

if __name__ == '__main__':
    if has_editable_in_hashed_install(sys.argv):
        print('ERROR: -e is incompatible with --require-hashes'); sys.exit(1)

Type guard

def is_editable_arg(arg: str) -> bool:
    return arg == '-e' or arg.startswith('-e ') or arg == '--editable' or arg.startswith('--editable=')

Try / catch

from subprocess import run
# Build the editable project to a wheel and install with hash instead.
run(["python", "-m", "build", "--wheel", project_dir], check=True)
run(["pip", "install", "--require-hashes", built_wheel], check=True)

Prevention

When it happens

Trigger: Calling 'pip install --require-hashes -e .' or including an editable requirement in a hashed install. The check is the very first thing prepare_editable_requirement does when self.require_hashes is True.

Common situations: Trying to lock down a project for reproducibility/security with --require-hashes while still developing an in-repo package with -e; a requirements file that combines hashes and an -e line.

Related errors


AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08). Data as JSON: /api/errors/c58bbe07b024dbc7. Report an issue: GitHub.

Appendix: source

Thrown at src/pip/_internal/operations/prepare.py:851

        download_location = join_within_directory(self.download_dir, link.filename)
        if not os.path.exists(download_location):
            shutil.copy(req.local_file_path, download_location)
            download_path = display_path(download_location)
            logger.info("Saved %s", download_path)

    def prepare_editable_requirement(
        self,
        req: InstallRequirement,
    ) -> BaseDistribution:
        """Prepare an editable requirement."""
        assert req.editable, "cannot prepare a non-editable req as editable"

        logger.info("Obtaining %s", req)

        with indent_log():
            if self.require_hashes:
                raise InstallationError(
                    f"The editable requirement {req} cannot be installed when "
                    "requiring hashes, because there is no single file to "
                    "hash."
                )
            req.ensure_has_source_dir(self.src_dir)
            req.update_editable()
            assert req.source_dir
            req.download_info = direct_url_for_editable(req.unpacked_source_directory)

            dist = _get_prepared_distribution(
                req,
                self.build_tracker,
                self.build_env_installer,
                self.build_isolation,
                self.check_build_deps,
                self.allow_editables,
            )

View on GitHub (pinned to f399c37189)