Skip to content

winget upgrade --all does not upgrade some apps

winget upgrade --all upgrades only what winget can safely and clearly upgrade. Some apps are skipped on purpose, and winget tells you why.

Winget’s documentation says upgrade --all upgrades “all installed applications that have an available update”. Two notes explain most surprises:

  • Some applications do not provide a version. Winget cannot know if a newer one exists, so they are not upgraded unless you add --include-unknown.
  • Applications that you pinned are not upgraded when you use --all, unless you add --include-pinned. That works for non-blocking pins only.

Look at the lines winget prints under the table. These are its exact texts:

Winget says What it means
N package(s) have version numbers that cannot be determined. Use --include-unknown to see all results. Unknown versions. They are left out.
N package(s) have pins that prevent upgrade. Use the 'winget pin' command to view and edit pins. Using the '--include-pinned' argument may show more results. Pinned packages are left out.
The following packages have an upgrade available, but require explicit targeting for upgrade: An upgrade exists, but it will not run with --all. Name the package.

Other apps fail during the upgrade and show an error code instead. The two most common are 0x80073D28 (needs administrator rights) and 0x8A150101 (the app is running).

In Update Everything, Devpit reads the winget table and the footer lines and shows you what happened:

  • Apps with an unknown version are not listed, and a note under winget says how many “apps with an unknown version aren’t shown”.
  • Pinned apps are left alone, and a note says how many (“pinned apps are left alone”). Pinned Chocolatey apps and held Scoop apps appear in the list as pinned or held and are not ticked.
  • Packages that winget says need explicit targeting are listed as needs explicit upgrade and are not ticked.
  • For every app you tick, Devpit runs winget upgrade with that app’s exact ID (--id and -e), silent, with the agreement flags, so the upgrade never waits for a prompt nobody can see.

Devpit never adds --include-unknown or --include-pinned for you. Pins are your decision.

  1. See what winget offers. Run this and read the lines under the table:
Terminal window
winget upgrade
  1. To include apps with an unknown version:
Terminal window
winget upgrade --all --include-unknown
  1. To include apps with a normal (non-blocking) pin:
Terminal window
winget upgrade --all --include-pinned
  1. To see your pins and remove one you no longer want:
Terminal window
winget pin list
winget pin remove --id Publisher.PackageName
  1. To upgrade one package by exact ID:
Terminal window
winget upgrade --id Publisher.PackageName -e

Use --include-unknown with care. Winget cannot read the current version of those apps, so it cannot tell whether an upgrade is needed.

Common questions

What does --include-unknown do?

Microsoft's documentation says it upgrades packages even if their current version cannot be determined. Some apps do not report a version, so winget cannot tell if a newer one exists. Without this flag, winget upgrade --all skips them.

What is the difference between a pin and a blocking pin?

A normal pin excludes the package from winget upgrade --all but still allows winget upgrade for that package, and --include-pinned lets --all include it. A blocking pin blocks both, so you have to remove the pin, or use --force.

Does Devpit run winget upgrade --include-unknown?

No. Devpit does not upgrade apps whose version is unknown. It tells you how many were left out, and it does not touch pinned apps.