Pinning a Bower Dependency to a Specific Git Tag or Commit
Learn how to lock a front‑end package to an exact Git reference in bower.json to achieve reproducible builds and avoid unexpected updates.
26 May 2026, 02:28 UTC

Desired outcome
Ensure a front‑end dependency installed via Bower is fixed to a known Git tag or commit so that subsequent builds retrieve the exact same source, preventing unexpected updates or breaking changes.
Prerequisites
- Node.js installed (any version that still supports the global Bower package; e.g., Node 12‑14 works with Bower 1.8.x).
- Bower installed globally:
npm install -g bower(requires permission to write to the global npm directory; usesudoon Linux/macOS if needed). - An existing project with a
bower.jsonfile. - Git available in the PATH for fetching remote repositories.
Procedure
- Identify the target reference. Decide whether you want to lock to a tag (e.g.,
v3.5.1) or a specific commit hash (e.g.,a1b2c3d4e5f6...). You can list tags withgit ls-remote --tagsor view commits withgit ls-remote --heads. - Edit
bower.json. Locate the dependency entry and replace its value with a Git URL followed by#and the reference.{ "name": "my-project", "dependencies": { "jquery": "git://github.com/jquery/jquery.git#3.5.1", "lodash": "git://github.com/lodash/lodash.git#a1b2c3d4e5f6g7h8i9j0" } }If the package is already registered in the Bower registry, you can also use the shorthand
jquery#3.5.1. - Install or reinstall the dependency. Run the command in the project directory:
bower installThis will fetch the specified Git reference and place the files under
bower_components/<package-name>/. - Verify the installed reference. Navigate to the component’s directory and check the Git HEAD:
cd bower_components/jquery git rev-parse HEADThe output should match the commit hash associated with the tag or commit you specified. You can also run
bower listto see a tree of installed packages and their sources.
Expected checks
bower listshows each dependency with the exact Git reference you set (e.g.,jquery#3.5.1).- The
git rev-parse HEADcommand inside each component returns a hash that matches the tag/commit you locked to. - Building your project (e.g., running your usual gulp/webpack task) completes without errors, confirming the assets are usable.
Recovery options (rollback)
If you need to revert to a previously floating version:
- Edit
bower.jsonand change the dependency back to a version range, a different tag, or remove the#suffix to let Bower pick the latest. - Run
bower installagain to fetch the new version. - Optionally clean the Bower cache to avoid using stale data:
bower cache clean.
Limitations and practical notes
- Bower is unmaintained; compatibility with newer Node.js versions may require using an older Node release or setting
--allow-rooton CI systems. - The Git reference method works only for dependencies sourced from a Git URL or a Bower‑registered package that maps to a Git repo. It does not work with plain ZIP URLs.
- Because Bower does not generate a lockfile, you must manually commit the updated
bower.jsonto version control to ensure reproducibility across environments. - Security advisories for Bower are sparse; verify that the Git reference points to a reputable repository and consider monitoring the upstream project for vulnerabilities.
Quick example
Suppose you want to lock the Bootstrap library to the v4.6.2 tag:
{
"name": "my-app",
"dependencies": {
"bootstrap": "git://github.com/twbs/bootstrap.git#v4.6.2"
}
}
Run bower install, then check:
cd bower_components/bootstrap
git rev-parse HEAD
# Expected: hash matching tag v4.6.2
If the hash matches, your build will always receive Bootstrap 4.6.2 regardless of newer releases published to the Bower registry.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.