pip install --require-hashes
Find out what the pain points are for projects which want to use reproducible builds with pip, and fix them.
https://pip.pypa.io/en/stable/topics/secure-installs/