Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codecov.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/codecov.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codecov.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/codecov.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codecov.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/codecov.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codecov.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/codecov.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/command-pr-integration-tests.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/command-pr-integration-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/command-pr-integration-tests.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/command-pr-integration-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/examples.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/examples.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/examples.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/examples.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-build-tags.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-build-tags.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-build-tags.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-build-tags.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-code-quality.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-code-quality.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-code-quality.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-code-quality.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-code-quality.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-code-quality.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-code-quality.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-code-quality.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-title.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-title.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-unit-tests.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-unit-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-unit-tests.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-unit-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-unit-tests.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-unit-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-unit-tests.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/andersfylling/disgord/pr-unit-tests.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating golang:1.18 to golang:1.18@sha256:50c889275d26f816b5314fc99f55425fa76b18fcaf16af255f5d57f09e1f48da
Warn: downloadThenRun not pinned by hash: .github/milestone-release.sh:8
Warn: downloadThenRun not pinned by hash: .github/workflows/codecov.yml:40
Warn: downloadThenRun not pinned by hash: .github/workflows/codecov.yml:63
Warn: goCommand not pinned by hash: .github/workflows/pr-code-quality.yml:36
Info: 0 out of 18 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 1 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 3 out of 4 goCommand dependencies pinned
Info: 0 out of 3 downloadThenRun dependencies pinned