hashin
Edits your requirements.txt by hashing them in
Decision gist · record as of 2026-08-14
Yes. hashin solves a real operational problem—automating hash generation for reproducible, verified package installations—with low install friction, active maintenance, no security vulnerabilities, and a permissive license. It is most valuable in deployment workflows where you want to enforce that production servers install only the exact packages you have vetted, but it requires discipline: you must manually inspect the downloaded files (via --verbose) to ensure they haven't been tampered with before committing the hashes.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.9 or later; downloads packages from PyPI over HTTPS during operation.
- Low friction: pure Python wheel with only packaging and pip as runtime dependencies.
- Active maintenance with recent releases; last commit 2026-08-03 and latest release 2025-06-12 indicate ongoing support.
License · maintenance · safety
MIT (permissive) — MIT license (permissive) imposes no restrictions on use, modification, or distribution in your own projects.
last release 2025-06-12 (428 days) · last repo commit 2026-08-03 · 108 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 142,940 downloads/mo, #11,194 on PyPI
Alternatives
Verify before relying
pip install hashin
hashin Django
# Or with specific version and output file:
hashin "requests==2.19.1" --requirements-file=requirements.txt- Whether the tool's hash verification workflow integrates with CI/CD systems or requires manual vetting steps beyond what the description shows.
- Performance characteristics when processing large numbers of packages or requirements files.
- Compatibility with private PyPI repositories or alternative package indexes.
What it is and what it does
hashin is a command-line tool that automates the tedious process of generating SHA256 (or other algorithm) hashes for Python packages and writing them into your requirements.txt file in a format compatible with pip's --require-hashes flag. Instead of manually downloading each package, running pip hash on each file, and editing requirements.txt, you run hashin with a package name or version specifier and it handles all those steps.
The tool downloads packages from PyPI over HTTPS, computes their hashes, and updates your requirements file with the hash-locked entries. It supports filtering by Python version (useful when a package has wheels for multiple Python versions), dry-run mode to preview changes, environment markers, and can be used both as a CLI tool and as a Python library. The underlying philosophy is that you vet the downloaded packages yourself (using the --verbose flag to inspect download locations) before committing the hashes, then deploy those hash-locked requirements to servers with confidence that the exact same packages will be installed.
Use it for
- Lock exact package versions and hashes in a development environment, then deploy those same hashes to production servers for reproducible installs.
- Add a new dependency to your requirements.txt with verified hashes without manually downloading and hashing each distribution file.
- Filter package hashes by Python version when a package offers wheels for multiple Python versions you don't all support.
- Preview changes to requirements.txt before committing them using --dry-run mode.
- Integrate hash-locked requirements into a deployment workflow where pip install --require-hashes enforces that only pre-vetted packages are installed.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
hashin solves a real operational problem—automating hash generation for reproducible, verified package installations—with low install friction, active maintenance, no security vulnerabilities, and a permissive license. It is most valuable in deployment workflows where you want to enforce that production servers install only the exact packages you have vetted, but it requires discipline: you must manually inspect the downloaded files (via --verbose) to ensure they haven't been tampered with before committing the hashes.
Install
hashin on PyPI
Before you install
Low friction: pure Python wheel with only packaging and pip as runtime dependencies. Active maintenance with recent releases; last commit 2026-08-03 and latest release 2025-06-12 indicate ongoing support.
Requires Python 3.9 or later; downloads packages from PyPI over HTTPS during operation.
License in practice
MIT license (permissive) imposes no restrictions on use, modification, or distribution in your own projects.
Quickstart
pip install hashin
hashin Django
# Or with specific version and output file:
hashin "requests==2.19.1" --requirements-file=requirements.txt
Verify before relying
- Whether the tool's hash verification workflow integrates with CI/CD systems or requires manual vetting steps beyond what the description shows.
- Performance characteristics when processing large numbers of packages or requirements files.
- Compatibility with private PyPI repositories or alternative package indexes.
Package facts
| License | MIT permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 2 packagespackagingpip |
| Maintenance | Actively maintained 428 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 142,940 / month, #11,194 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Intended Audience :: DevelopersIntended Audience :: System AdministratorsProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Topic :: Software Development :: Build ToolsTopic :: System :: Installation/SetupTopic :: System :: Systems Administration |
Evidence: hashin-1.0.5-py2.py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “requirements.txt hash generator”
- hashinAutomates the process of adding cryptographic hashes to your…
- pipenvPipenv automates Python virtual environment creation and dependency…
- to-requirements.txtAutomatically synchronizes your project's requirements.txt with…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also requirementslib · pip-api · requirements-detector · filehash · pipfile · pip-tools · requirements-parser · poetry-plugin-export · blurhash-python · django-sri