winget upgrade --all does not upgrade some apps
winget upgrade --all upgrades only what winget can safely and clearly upgrade. Some apps are skipped on purpose, and winget tells you why.
What it means
Section titled “What it means”Winget’s documentation says upgrade --all upgrades “all installed applications that have an available update”. Two notes explain most surprises:
- Some applications do not provide a version. Winget cannot know if a newer one exists, so they are not upgraded unless you add
--include-unknown. - Applications that you pinned are not upgraded when you use
--all, unless you add--include-pinned. That works for non-blocking pins only.
Why it happens
Section titled “Why it happens”Look at the lines winget prints under the table. These are its exact texts:
| Winget says | What it means |
|---|---|
N package(s) have version numbers that cannot be determined. Use --include-unknown to see all results. |
Unknown versions. They are left out. |
N package(s) have pins that prevent upgrade. Use the 'winget pin' command to view and edit pins. Using the '--include-pinned' argument may show more results. |
Pinned packages are left out. |
The following packages have an upgrade available, but require explicit targeting for upgrade: |
An upgrade exists, but it will not run with --all. Name the package. |
Other apps fail during the upgrade and show an error code instead. The two most common are 0x80073D28 (needs administrator rights) and 0x8A150101 (the app is running).
How Devpit fixes or avoids it
Section titled “How Devpit fixes or avoids it”In Update Everything, Devpit reads the winget table and the footer lines and shows you what happened:
- Apps with an unknown version are not listed, and a note under winget says how many “apps with an unknown version aren’t shown”.
- Pinned apps are left alone, and a note says how many (“pinned apps are left alone”). Pinned Chocolatey apps and held Scoop apps appear in the list as pinned or held and are not ticked.
- Packages that winget says need explicit targeting are listed as needs explicit upgrade and are not ticked.
- For every app you tick, Devpit runs
winget upgradewith that app’s exact ID (--idand-e), silent, with the agreement flags, so the upgrade never waits for a prompt nobody can see.
Devpit never adds --include-unknown or --include-pinned for you. Pins are your decision.
The manual fix
Section titled “The manual fix”- See what winget offers. Run this and read the lines under the table:
winget upgrade- To include apps with an unknown version:
winget upgrade --all --include-unknown- To include apps with a normal (non-blocking) pin:
winget upgrade --all --include-pinned- To see your pins and remove one you no longer want:
winget pin listwinget pin remove --id Publisher.PackageName- To upgrade one package by exact ID:
winget upgrade --id Publisher.PackageName -eUse --include-unknown with care. Winget cannot read the current version of those apps, so it cannot tell whether an upgrade is needed.
Sources
Section titled “Sources”Common questions
What does --include-unknown do?
Microsoft's documentation says it upgrades packages even if their current version cannot be determined. Some apps do not report a version, so winget cannot tell if a newer one exists. Without this flag, winget upgrade --all skips them.
What is the difference between a pin and a blocking pin?
A normal pin excludes the package from winget upgrade --all but still allows winget upgrade for that package, and --include-pinned lets --all include it. A blocking pin blocks both, so you have to remove the pin, or use --force.
Does Devpit run winget upgrade --include-unknown?
No. Devpit does not upgrade apps whose version is unknown. It tells you how many were left out, and it does not touch pinned apps.
