pip requirements.txt With Pinned Hashes
A hash-pinned pip requirements file with two sha256 hashes per fictional package (wheel and sdist) and line continuations: the form `--require-hashes` installs demand. Every package, version, hash and licence is fictional: the tree describes nothing real.
# SAMPLE — fictional supply-chain data. Every package, registry, version, hash, licence, advisory identifier and signature in this document is invented.
# Generated by `pip-compile --generate-hashes` (fictional run).
example-router==2.1.3 \
--hash=sha256:e9624300914e1080d644230a8c0525f4ad46fa4746ec645075cb844272160d35 \
--hash=sha256:2a2b95d78904b0009e3c052e906b2c6a0691b0b626a7b057d826649297fb440a
example-http-core==1.8.0 \
--hash=sha256:bb7704d94f653fb47f23b1da317f7d5eba44c364e604e8cafefa1efbeb3234b7 \
--hash=sha256:ab38730eb7cbc79a1fc844da7a11f8a47942c21e4abb34f9d130abfa29282f3b
example-metrics==4.0.0 \
--hash=sha256:b875a156a9c1232e21eceb1d32c2f57926b0e983a11596dbe606936d2c4e09e3 \
--hash=sha256:f0e52181da7e02f455615f82efc4dc323324cd57d3406486e20285e41df506c2
example-cache==0.9.2 \
--hash=sha256:5de14382108c7789a187a09ab6c574c833afa1446d1fda1e5628c4de4240fb50 \
--hash=sha256:f79da81a8b687e652a9933330eff345f2811af6e649942c289558c320d63d216
example-crypto-shim==1.2.0 \
--hash=sha256:6c33dab1efa1b12eb20a59138042be210ea5bba8eaa47f1cbed1e3734458d993 \
--hash=sha256:c0b988facd0856e0ee93e9976ec3f06bc1200675b94f3179a2ad824e853d0473
example-logger==3.4.1 \
--hash=sha256:1ad0aaa5a0e6c27f742494ecaef51a20dc7fca52cc7575814488d10abd47725c \
--hash=sha256:4a0afb7a9683ce63cc7b02d2abf964f125b0f15c7c35e048dee04f010446b74d
example-retry==1.0.4 \
--hash=sha256:b5b5355e9665f539aa680637aaffbed0675393b5b3b9ce302c0df2d8ade47bfb \
--hash=sha256:0ca940564c2bfdbc52a4c746b906265938c58d303cad46908d3027645e18920d
example-json-path==2.0.5 \
--hash=sha256:2c11a0236672ad43688bd3448f85c49b674246e5c5d66d1735dec218e15459f2 \
--hash=sha256:9be7a45dff321890cba57efdede756cee7c7e746dd41aaf10c074870334e7c1f
example-yaml-lite==1.1.7 \
--hash=sha256:3653b451056f9a114216490f67ac0b327baaa5b061dfc368498bd85d269dc432 \
--hash=sha256:95163238f6d883e96da20993e058f4499df33978e592ba326e3a4f1fc017a15d
Specifications
- Seed
- 51200
- Sample Only
- true
- Ecosystem
- pip
- Requirements
- 9
- Hashes Per Package
- 2
- Mode
- --require-hashes
- Line Endings
- LF
Testing contract
Expected to pass- Scenario
- Parse a requirements file that uses backslash continuations and multiple --hash options per requirement.
- Expected result
- Reader returns 9 requirements, each with exactly two sha256 hashes, rather than 27 malformed lines.
What is a .txt file?
TXT is a plain-text file containing unformatted character data with no styling or structure beyond line breaks. Its interpretation depends on character encoding, most commonly UTF-8, and on line-ending convention. It is the most universal and portable text container.
How to use this file
Use an example TXT to test encoding detection, line-ending (LF versus CRLF) handling, and any tool that reads or streams raw text input.
How to use this file for testing
“pip requirements.txt With Pinned Hashes” is a deterministic Testaroo fixture for Config parsing, Conversion testing, Schema validation. TOML and INI configuration files with nested sections and typed values, for testing config parsers and loaders.
Documented properties for this file: seed 51200 · LF. Compare results against paired or grouped companions on this page when present (clean↔damaged, searchable↔scanned, or format twins) so scores stay reproducible across runs.
Download the file once, keep the path stable in CI or local scripts, and treat the spec table as the contract: dimensions, seeds, field lists, and roles are intentional. Corrupt or invalid samples are labelled as such, expect parsers to fail loudly rather than silently accept them.
SBOM, lockfile, provenance, and advisory fixtures describe the same fabricated component tree across formats, so a converter or scanner can be diffed against a known answer. Every package name, version, hash, and advisory ID is invented, never treat a finding here as real.
Point your config loader at the file and assert it reads the documented sections and typed values, including any deliberately-tricky nesting or comments.
Generated by generation/supply_chain.py. Free for any use, no attribution required, license.
Related files
- lockCargo.lock (version 4)A Rust Cargo.lock in the version 4 format: TOML [[package]] tables with a registry source, a sha256-shaped checksum and a name-only dependencies array that resolves against the other tables. Every package, version, hash and licence is fictional: the tree describes nothing real.

- spdxSPDX 2.2 Legacy SBOM (Tag-Value)The same fictional tree as an SPDX 2.2 tag-value document (the version still produced by older toolchains) for upgrade and compatibility tests against the 2.3 twin in this family. Every package, version, hash and licence is fictional: the tree describes nothing real.

- yamlSPDX 2.3 Application SBOM (YAML)The SPDX 2.3 SBOM in its YAML serialisation: the third form the specification defines alongside JSON and tag-value, and the one most often hand-edited in a repository. Every package, version, hash and licence is fictional: the tree describes nothing real.

- spdxSPDX 2.3 SBOM With LicenseRef and Compound ExpressionsAn SPDX tag-value SBOM that declares a non-standard LicenseRef with its extracted text and uses it inside compound expressions: the case that breaks compliance tools which assume every licence is an SPDX id. Every package, version, hash and licence is fictional: the tree describes nothing real.

- lockCargo.lock (version 3, Legacy)The same fictional Rust tree pinned by a version 3 Cargo.lock, for testing that a reader keys on the declared version rather than assuming the newest format. Every package, version, hash and licence is fictional: the tree describes nothing real.

- jsonnpm package-lock.json (lockfileVersion 3)An npm lockfile in the modern v3 layout: a flat packages map keyed by node_modules path, with resolved tarball URLs and sha512 subresource integrity for nine fictional dependencies. Every package, version, hash and licence is fictional: the tree describes nothing real.
