pypa/pip · error · PylockValidationError
Version in is not consistent with package version
Error message
Version in {wheel.filename!r} is not consistent with package version {str(package.version)!r} What it means
PylockValidationError: the version parsed from a wheel filename disagrees with the package's declared 'version' field. This only fires when package.version is non-empty; PEP 751 requires the filename version to equal the package version so an installer never installs a file claiming a different release.
Solutions
- Check the version segment of every wheel filename (between the first and second dash) against the package's version field.
- Update the wheel filenames (or remove stale ones) so each matches the declared package version.
- Regenerate the lock so wheel filenames and the package version stay in sync.
- Re-run Pylock.validate().
Example fix
# before [[packages]] name = "requests" version = "2.31.0" [[packages.wheels]] filename = "requests-2.30.0-py3-none-any.whl" # after [[packages]] name = "requests" version = "2.31.0" [[packages.wheels]] filename = "requests-2.31.0-py3-none-any.whl"
Defensive patterns
Strategy: validation
Validate before calling
from packaging.utils import parse_wheel_filename
from packaging.version import Version
def wheel_version_consistent(filename: str, version: str) -> bool:
try:
_, ver, *_ = parse_wheel_filename(filename)
except Exception:
return False
return not version or Version(str(ver)) == Version(version)
for p in toml_dict.get('packages', []):
v = p.get('version')
for w in p.get('wheels', []) or []:
assert wheel_version_consistent(w['filename'], v), (w['filename'], v) Type guard
null
Try / catch
try:
Pylock.from_dict(toml_dict)
except PylockValidationError as e:
# e.context names wheels[i]; align its version segment with package.version
report(e.context, e.message) Prevention
- When bumping a package version, refresh every wheel filename in that package block in the same edit.
- Discard stale wheels from the entry; do not carry old releases forward.
- Let the locker own filename/version coherence; avoid hand-edits.
When it happens
Trigger: Package validation iterates wheels; for each, parse_wheel_filename yields a version that is compared (after PEP 440 normalization) to package.version. Fires when e.g. version="2.31.0" but a wheel is named 'requests-2.30.0-py3-none-any.whl', or a wheel for an older build was left in the entry.
Common situations: Partial lock update where the package version was bumped but the old wheel filenames were not refreshed; a stale wheel cached and re-recorded by a buggy locker; local-version or post-version spelling differences that normalize differently.
Related errors
- Invalid wheel filename
- Name in is not consistent with package name
- Version in is not consistent with package version
- Cannot determine wheel filename
- Invalid sdist filename
AI-assisted analysis of pypa/pip@f399c37189 (2026-08-08).
Data as JSON: /api/errors/d5903571b7065fb6.
Report an issue: GitHub.
Appendix: source
Thrown at src/pip/_vendor/packaging/pylock.py:628
"Exactly one of vcs, directory, archive must be set "
"if sdist and wheels are not set"
)
for i, wheel in enumerate(package.wheels or []):
try:
(name, version, _, _) = parse_wheel_filename(wheel.filename)
except Exception as e:
raise PylockValidationError(
f"Invalid wheel filename {wheel.filename!r}",
context=f"wheels[{i}]",
) from e
if name != package.name:
raise PylockValidationError(
f"Name in {wheel.filename!r} is not consistent with "
f"package name {package.name!r}",
context=f"wheels[{i}]",
)
if package.version and version != package.version:
raise PylockValidationError(
f"Version in {wheel.filename!r} is not consistent with "
f"package version {str(package.version)!r}",
context=f"wheels[{i}]",
)
if package.sdist:
try:
name, version = parse_sdist_filename(package.sdist.filename)
except Exception as e:
raise PylockValidationError(
f"Invalid sdist filename {package.sdist.filename!r}",
context="sdist",
) from e
if name != package.name:
raise PylockValidationError(
f"Name in {package.sdist.filename!r} is not consistent with "
f"package name {package.name!r}",
context="sdist",
)View on GitHub (pinned to f399c37189)