$npx skillfedfor your agent

hashin

Edits your requirements.txt by hashing them in

Worth itPyPI Build ToolsReleased Jun 2025142.9K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — hashin-1.0.5-py2.py3-none-any.whl
v1.0.5 · released 2025-06-12 · Python >=3.9 · 2 runtime deps: packaging, pip

Yes. hashin solves a real operational problem—automating hash generation for reproducible, verified package installations—with low install friction, active maintenance, no security vulnerabilities, and a permissive license. It is most valuable in deployment workflows where you want to enforce that production servers install only the exact packages you have vetted, but it requires discipline: you must manually inspect the downloaded files (via --verbose) to ensure they haven't been tampered with before committing the hashes.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later; downloads packages from PyPI over HTTPS during operation.
  • Low friction: pure Python wheel with only packaging and pip as runtime dependencies.
  • Active maintenance with recent releases; last commit 2026-08-03 and latest release 2025-06-12 indicate ongoing support.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) imposes no restrictions on use, modification, or distribution in your own projects.

last release 2025-06-12 (428 days) · last repo commit 2026-08-03 · 108 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 142,940 downloads/mo, #11,194 on PyPI

Verify before relying

pip install hashin

hashin Django

# Or with specific version and output file:
hashin "requests==2.19.1" --requirements-file=requirements.txt
  • Whether the tool's hash verification workflow integrates with CI/CD systems or requires manual vetting steps beyond what the description shows.
  • Performance characteristics when processing large numbers of packages or requirements files.
  • Compatibility with private PyPI repositories or alternative package indexes.
Same gist for agents: .md · .json

What it is and what it does

hashin is a command-line tool that automates the tedious process of generating SHA256 (or other algorithm) hashes for Python packages and writing them into your requirements.txt file in a format compatible with pip's --require-hashes flag. Instead of manually downloading each package, running pip hash on each file, and editing requirements.txt, you run hashin with a package name or version specifier and it handles all those steps.

The tool downloads packages from PyPI over HTTPS, computes their hashes, and updates your requirements file with the hash-locked entries. It supports filtering by Python version (useful when a package has wheels for multiple Python versions), dry-run mode to preview changes, environment markers, and can be used both as a CLI tool and as a Python library. The underlying philosophy is that you vet the downloaded packages yourself (using the --verbose flag to inspect download locations) before committing the hashes, then deploy those hash-locked requirements to servers with confidence that the exact same packages will be installed.

Use it for

  • Lock exact package versions and hashes in a development environment, then deploy those same hashes to production servers for reproducible installs.
  • Add a new dependency to your requirements.txt with verified hashes without manually downloading and hashing each distribution file.
  • Filter package hashes by Python version when a package offers wheels for multiple Python versions you don't all support.
  • Preview changes to requirements.txt before committing them using --dry-run mode.
  • Integrate hash-locked requirements into a deployment workflow where pip install --require-hashes enforces that only pre-vetted packages are installed.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

hashin solves a real operational problem—automating hash generation for reproducible, verified package installations—with low install friction, active maintenance, no security vulnerabilities, and a permissive license. It is most valuable in deployment workflows where you want to enforce that production servers install only the exact packages you have vetted, but it requires discipline: you must manually inspect the downloaded files (via --verbose) to ensure they haven't been tampered with before committing the hashes.

Install

hashin on PyPI

Before you install

Low friction: pure Python wheel with only packaging and pip as runtime dependencies. Active maintenance with recent releases; last commit 2026-08-03 and latest release 2025-06-12 indicate ongoing support.

Requires Python 3.9 or later; downloads packages from PyPI over HTTPS during operation.

License in practice

MIT license (permissive) imposes no restrictions on use, modification, or distribution in your own projects.

Quickstart

pip install hashin

hashin Django

# Or with specific version and output file:
hashin "requests==2.19.1" --requirements-file=requirements.txt

Verify before relying

  • Whether the tool's hash verification workflow integrates with CI/CD systems or requires manual vetting steps beyond what the description shows.
  • Performance characteristics when processing large numbers of packages or requirements files.
  • Compatibility with private PyPI repositories or alternative package indexes.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
2 packages
packagingpip
MaintenanceActively maintained 428 days since the last release
Last repo commit
First released
Downloads142,940 / month, #11,194 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Intended Audience :: DevelopersIntended Audience :: System AdministratorsProgramming Language :: Python :: 3Programming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Topic :: Software Development :: Build ToolsTopic :: System :: Installation/SetupTopic :: System :: Systems Administration

Evidence: hashin-1.0.5-py2.py3-none-any.whl

Tags

Capabilities
requirements.txt hash generatorpip hash automationreproducible python dependenciesrequirements file securitypackage integrity verificationpip install --require-hashesdependency hash management
Topics
dependency-managementreproducible-buildssecurity-hardening
PyPI keywords
piprepeatabledeploydeploymenthashinstallinstaller

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “requirements.txt hash generator”

  • hashinAutomates the process of adding cryptographic hashes to your…
  • pipenvPipenv automates Python virtual environment creation and dependency…
  • to-requirements.txtAutomatically synchronizes your project's requirements.txt with…

Give your agent the search over MCP, or paste the wish link into any chat.

More Build Tools packages

packaging Worth it
PyPI · Build Tools · released Aug 2026

Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.

Apache-2.0 OR BSD-2-Clausepure Python · 3.9+
2.2Bdownloads / mo
tqdm Worth it
PyPI · Libraries · released Jul 2026

Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.

copyleftpure Python · 3.8+
648.6Mdownloads / mo
pip Worth it
PyPI · Build Tools · released Aug 2026

pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.

MITpure Python · 3.10+
617.5Mdownloads / mo
hatchling Worth it
PyPI · Python Modules · released Aug 2026

Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.

MITpure Python · 3.10+
484.2Mdownloads / mo
grpcio-tools Worth it
PyPI · Build Tools · released Jul 2026

Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.

Apache-2.0compiled wheel · 3.10+
278.2Mdownloads / mo
pre-commit Worth it
PyPI · Build Tools · released Aug 2026

pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.

Install it if your team needs consistent, automated validation at commit time.

permissive licensepure Python · 3.10+
179.9Mdownloads / mo

See also requirementslib · pip-api · requirements-detector · filehash · pipfile · pip-tools · requirements-parser · poetry-plugin-export · blurhash-python · django-sri