pypa/pip · error · PylockValidationError

Version in is not consistent with package version

Error message

Version in {wheel.filename!r} is not consistent with package version {str(package.version)!r}

What it means

PylockValidationError: the version parsed from a wheel filename disagrees with the package's declared 'version' field. This only fires when package.version is non-empty; PEP 751 requires the filename version to equal the package version so an installer never installs a file claiming a different release.

Solutions

  1. Check the version segment of every wheel filename (between the first and second dash) against the package's version field.
  2. Update the wheel filenames (or remove stale ones) so each matches the declared package version.
  3. Regenerate the lock so wheel filenames and the package version stay in sync.
  4. Re-run Pylock.validate().

Example fix

# before
[[packages]]
name = "requests"
version = "2.31.0"
  [[packages.wheels]]
  filename = "requests-2.30.0-py3-none-any.whl"

# after
[[packages]]
name = "requests"
version = "2.31.0"
  [[packages.wheels]]
  filename = "requests-2.31.0-py3-none-any.whl"
Defensive patterns

Strategy: validation

Validate before calling

from packaging.utils import parse_wheel_filename
from packaging.version import Version

def wheel_version_consistent(filename: str, version: str) -> bool:
    try:
        _, ver, *_ = parse_wheel_filename(filename)
    except Exception:
        return False
    return not version or Version(str(ver)) == Version(version)

for p in toml_dict.get('packages', []):
    v = p.get('version')
    for w in p.get('wheels', []) or []:
        assert wheel_version_consistent(w['filename'], v), (w['filename'], v)

Type guard

null

Try / catch

try:
    Pylock.from_dict(toml_dict)
except PylockValidationError as e:
    # e.context names wheels[i]; align its version segment with package.version
    report(e.context, e.message)

Prevention

When it happens

Trigger: Package validation iterates wheels; for each, parse_wheel_filename yields a version that is compared (after PEP 440 normalization) to package.version. Fires when e.g. version="2.31.0" but a wheel is named 'requests-2.30.0-py3-none-any.whl', or a wheel for an older build was left in the entry.

Common situations: Partial lock update where the package version was bumped but the old wheel filenames were not refreshed; a stale wheel cached and re-recorded by a buggy locker; local-version or post-version spelling differences that normalize differently.

Related errors


AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08). Data as JSON: /api/errors/d5903571b7065fb6. Report an issue: GitHub.

Appendix: source

Thrown at src/pip/_vendor/packaging/pylock.py:628

                "Exactly one of vcs, directory, archive must be set "
                "if sdist and wheels are not set"
            )
        for i, wheel in enumerate(package.wheels or []):
            try:
                (name, version, _, _) = parse_wheel_filename(wheel.filename)
            except Exception as e:
                raise PylockValidationError(
                    f"Invalid wheel filename {wheel.filename!r}",
                    context=f"wheels[{i}]",
                ) from e
            if name != package.name:
                raise PylockValidationError(
                    f"Name in {wheel.filename!r} is not consistent with "
                    f"package name {package.name!r}",
                    context=f"wheels[{i}]",
                )
            if package.version and version != package.version:
                raise PylockValidationError(
                    f"Version in {wheel.filename!r} is not consistent with "
                    f"package version {str(package.version)!r}",
                    context=f"wheels[{i}]",
                )
        if package.sdist:
            try:
                name, version = parse_sdist_filename(package.sdist.filename)
            except Exception as e:
                raise PylockValidationError(
                    f"Invalid sdist filename {package.sdist.filename!r}",
                    context="sdist",
                ) from e
            if name != package.name:
                raise PylockValidationError(
                    f"Name in {package.sdist.filename!r} is not consistent with "
                    f"package name {package.name!r}",
                    context="sdist",
                )

View on GitHub (pinned to f399c37189)