Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_m1.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/build_m1.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_m1.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/build_m1.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_m1.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/build_m1.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codespell.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/codespell.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/codespell.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/codespell.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/golangci-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/trivy.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/trivy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/trivy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-wiki-docs.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/update-wiki-docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-wiki-docs.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/update-wiki-docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-wiki-docs.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/update-wiki-docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-wiki-docs.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/Azure/azure-storage-azcopy/update-wiki-docs.yml/main?enable=pin
Warn: containerImage not pinned by hash: docker/Dockerfile:2: pin your Docker image by updating mcr.microsoft.com/mirror/docker/library/ubuntu:22.04 to mcr.microsoft.com/mirror/docker/library/ubuntu:22.04@sha256:d80997daaa3811b175119350d84305e1ec9129e1799bba0bd1e3120da3ff52c3
Warn: containerImage not pinned by hash: docker/DockerfileArm64:2: pin your Docker image by updating mcr.microsoft.com/mirror/docker/library/ubuntu:22.04 to mcr.microsoft.com/mirror/docker/library/ubuntu:22.04@sha256:d80997daaa3811b175119350d84305e1ec9129e1799bba0bd1e3120da3ff52c3
Warn: containerImage not pinned by hash: docker/DockerfileMariner:2: pin your Docker image by updating mcr.microsoft.com/cbl-mariner/base/core:2.0 to mcr.microsoft.com/cbl-mariner/base/core:2.0@sha256:961bfedbbbdc0da51bc664f51d959da292eced1ad46c3bf674aba43b9be8c703
Warn: containerImage not pinned by hash: docker/DockerfileMarinerArm64:2: pin your Docker image by updating mcr.microsoft.com/cbl-mariner/base/core:2.0 to mcr.microsoft.com/cbl-mariner/base/core:2.0@sha256:961bfedbbbdc0da51bc664f51d959da292eced1ad46c3bf674aba43b9be8c703
Info: 0 out of 16 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 3 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned