为何PyPI切换python-crontab 2.6.0哈希类型导致构建失败?
为什么固定版本的python-crontab突然出现哈希不匹配错误?
核心原因
你上传python-crontab 2.7.0到PyPI后,PyPI上的2.6.0版本被补充了wheel格式的分发包(之前可能只有源码tar.gz包)。你的Pipfile.lock里只记录了源码包的SHA256哈希值,但现在pip会优先下载安装更快的wheel包,两个文件哈希自然不同,导致验证失败。
关于哈希验证的误区
- 哈希验证的是单个分发文件的完整性,不是版本本身。同一个版本的源码包和wheel包是完全不同的文件,哈希值必然不一样。
- 哈希确实能防供应链劫持,但这次不是被篡改,而是该版本的可用分发文件变多了,你的锁文件没覆盖到新文件的哈希。
为什么上传新版本会影响旧版本?
PyPI允许包维护者为已发布的旧版本补充上传新的分发格式(比如后续补上wheel包)。你上传2.7.0时可能触发了相关维护操作,或者维护者事后为2.6.0添加了wheel包,导致PyPI上2.6.0的可用文件集合发生了变化。
解决办法
- 更新锁文件:运行
pipenv lock重新生成锁文件,新的锁文件会包含该版本所有可用分发包的哈希值,这样不管pip下载源码包还是wheel包都能通过验证。 - (不推荐)强制使用源码包:在Pipfile中添加
--no-binary python-crontab,强制pip下载源码包,但会降低安装效率。
相关错误日志
#0 18.96 [pipenv.exceptions.InstallError]: Using cached python_crontab-2.6.0-py3-none-any.whl (25 kB) #0 18.96 [pipenv.exceptions.InstallError]: ERROR: THESE PACKAGES DO NOT MATCH THE HASHES FROM THE REQUIREMENTS FILE. If you have updated the package versions, please update the hashes. Otherwise, examine the package contents carefully; someone may have tampered with them. #0 18.96 [pipenv.exceptions.InstallError]: python-crontab==2.6.0 from https://files.pythonhosted.org/packages/8a/65/ee4f4db956d14b42aa6cf0dbd0b77217a206484b99f1d4aa11326cd3952a/python_crontab-2.6.0-py3-none-any.whl (from -r /tmp/pipenv-om9jbtdi-requirements/pipenv-0ytg305b-hashed-reqs.txt (line 80)): #0 18.96 [pipenv.exceptions.InstallError]: Expected sha256 1e35ed7a3cdc3100545b43e196d34754e6551e7f95e4caebbe0e1c0ca41c2f1b #0 18.96 [pipenv.exceptions.InstallError]: Got f308a64b8b1d072da4a235e9320398a242e92d080c1d8143bd0c600b24e160f8 #0 18.96 ERROR: Couldn't install package: [omitted for length]
流水线执行错误
------ failed to solve: executor failed running [/bin/sh -c pipenv install --dev --system --deploy]: exit code: 1 Exited with code exit status 17
锁文件片段
"python-crontab": { "hashes": [ "sha256:1e35ed7a3cdc3100545b43e196d34754e6551e7f95e4caebbe0e1c0ca41c2f1b" ], "index": "pypi", "version": "==2.6.0" },
内容的提问来源于stack exchange,提问作者Andrew
相关产品推荐
相关产品推荐

