The Windows Package Manager (winget) has revolutionised software management on Windows 11. Running a simple command like winget upgrade --all allows power users and system administrators to update dozens of installed applications, utilities, and developer runtimes simultaneously in seconds. However, this convenient batch updating power comes with an inherent operational risk: automated upgrades can inadvertently break mission-critical tools.
Certain software suites—such as specialized audio production plugins, legacy enterprise VPN clients, database servers, or custom development runtimes—rely on strict, tested version numbers. Upgrading these apps automatically can lead to compatibility crashes or licensing errors. To prevent unwanted updates during bulk maintenance, winget includes a robust package pinning utility: the winget pin command.
Understanding Pin Types in winget
The winget pinning architecture offers two distinct pin types, giving you precise control over update behaviour:
- Pinning to a Specific Version (Blocking All Updates): Completely prevents winget from touching the application. Even if you explicitly run
winget upgrade --all, the package is skipped entirely and kept at its current installed version. - Pinning to a Major or Minor Release Pattern (Gating Updates): Restricts updates to a specific semantic versioning pattern. For example, you can allow an application to receive minor bug fixes and security patches (e.g.
2.4.x) while blocking major version upgrades (e.g.3.0.0) that might introduce breaking configuration changes.
Basic Syntax of the winget pin Command
The pinning system is managed through three primary subcommands:
winget pin add <package-id> [options] # Creates a new pin rule
winget pin list # Displays all currently active pins
winget pin remove <package-id> # Deletes an existing pin rule
Step 1: Locating the Package Identifier
To avoid pinning the wrong application, always locate the exact official Package ID before creating a pin:
- Open Windows Terminal, PowerShell, or Command Prompt.
- Search for your installed application using:
winget list <app-name> - Inspect the output to find the exact string in the Id column (for example,
Git.Git,Oracle.JDK.17, orVideoLAN.VLC).
Step 2: Pinning an Application to Block All Upgrades
To completely freeze an installed application at its current version and prevent winget from ever updating it during winget upgrade --all, execute:
winget pin add --id VideoLAN.VLC --blocking
The --blocking flag instructs the Windows Package Manager that this application must be strictly preserved. The terminal outputs a confirmation: “Successfully added pin for package: VideoLAN.VLC”.
If you run winget upgrade later, the pinned package will either be omitted from the list of available upgrades or flagged with an explicit pin notice, ensuring that your system remains untouched.
Step 3: Gating Updates to a Specific Version Pattern
If you want to allow minor stability and patch updates while blocking major overhauls, specify the target version pattern with the --version argument:
winget pin add --id Python.Python.3.11 --version 3.11.*
Under this configuration, winget will happily install version 3.11.9 or 3.11.10 when released, but it will firmly refuse to upgrade your Python environment to Python 3.12.
Inspecting All Active Pins on Your System
To audit which applications are currently shielded from updates, run the list command:
winget pin list
Windows Terminal outputs a structured table detailing:
| Column | What It Tells You |
|---|---|
| Name | The human-readable title of the application. |
| Id | The unique repository package identifier. |
| Version | The pinned version boundary (e.g. * or a wildcard pattern). |
| Type | Indicates whether the pin is Pinning or Blocking. |
| Source | The package repository source (typically winget or msstore). |
Removing a Pin to Resume Standard Upgrades
When you are ready to update the pinned package—such as when a compatibility bug has been resolved by the vendor—remove the pin rule:
winget pin remove --id VideoLAN.VLC
Once removed, the package is re-evaluated during standard update cycles, and running winget upgrade --all will immediately update the program to the latest upstream release.
Bypassing Pins Manually When Needed
If you have pinned an application to protect it from automated scripts, but you intentionally want to perform a manual upgrade right now without deleting your pin, use the --force flag:
winget upgrade --id VideoLAN.VLC --force
The --force parameter acknowledges the active pin rule, overrides the restriction for this single manual execution, and applies the upgrade while leaving the pin rule intact for future batch runs.
By integrating the winget pin command into your Windows 11 administration routine, you enjoy the full velocity of automated software package updates without risking system stability.