This is progress: pip 8 has a “hash checking mode” to help mitigate some tampering attacks: https://pip.readthedocs.org/en/stable/reference/pip_install/#hash-checking-mode

@williballenthin