# Hashes enable pip's hash-checking mode (see
# https://pip.pypa.io/en/stable/topics/secure-installs/#hash-checking-mode),
# required via --require-hashes in the Dockerfile. When bumping the version,
# regenerate both hashes for the new release:
#   pip download --no-deps codespell==<version>            # wheel
#   pip download --no-deps --no-binary :all: codespell==<version>  # sdist
#   pip hash <each downloaded file>
codespell[toml]==2.4.3 \
    --hash=sha256:af2505b335e8573dbd2d384d1c4ef498f4006f4ba2d6fceca01e55b91f52628a \
    --hash=sha256:cbe085e331227b37bb86ef8bddd08dc768c704ee9a07ca869852c093fa2793e2
