Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bugs.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/bugs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bugs.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/bugs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bugs.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/bugs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-quality.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/code-quality.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-quality.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/code-quality.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-quality.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/code-quality.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-quality.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/code-quality.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-image.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/docker-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-generics.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-generics.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-generics.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-generics.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-generics.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-generics.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-mac.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-mac.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-mac.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-mac.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-mac.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-mac.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-releases.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-releases.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-releases.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-releases.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-releases.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go-releases.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/licenses.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/licenses.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/licenses.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/licenses.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/licenses.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/licenses.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/licenses.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/licenses.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/licenses.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/licenses.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/nightly.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/nightly.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/nightly.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/nightly.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly2.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/nightly2.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly2.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/nightly2.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly2.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/nightly2.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly2.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/CS-SI/SafeScale/nightly2.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile.cover.local:1
Warn: containerImage not pinned by hash: Dockerfile.cover.local:38
Warn: containerImage not pinned by hash: Dockerfile.cover.local:90
Warn: containerImage not pinned by hash: Dockerfile.current:1
Warn: containerImage not pinned by hash: Dockerfile.current:38
Warn: containerImage not pinned by hash: Dockerfile.current:88: pin your Docker image by updating golang:1.18.4-alpine to golang:1.18.4-alpine@sha256:9b2a2799435823dbf6fef077a8ff7ce83ad26b382ddabf22febfc333926400e4
Warn: containerImage not pinned by hash: Dockerfile.local:1
Warn: containerImage not pinned by hash: Dockerfile.local:38
Warn: containerImage not pinned by hash: Dockerfile.local:90
Warn: containerImage not pinned by hash: build/Dockerfile:1
Warn: containerImage not pinned by hash: build/Dockerfile:39
Warn: containerImage not pinned by hash: build/Dockerfile:89
Warn: containerImage not pinned by hash: build/Dockerfile.ci:1
Warn: containerImage not pinned by hash: build/Dockerfile2:1
Warn: containerImage not pinned by hash: build/Dockerfile2:41
Warn: containerImage not pinned by hash: build/Dockerfile2:91
Warn: downloadThenRun not pinned by hash: lib/backend/iaas/userdata/newscripts/userdata.final.sh:114
Warn: downloadThenRun not pinned by hash: lib/backend/iaas/userdata/newscripts/userdata.final.sh:127
Warn: downloadThenRun not pinned by hash: lib/backend/iaas/userdata/newscripts/userdata.netsec.sh:1328
Warn: downloadThenRun not pinned by hash: lib/backend/iaas/userdata/newscripts/userdata.netsec.sh:1341
Warn: downloadThenRun not pinned by hash: lib/backend/iaas/userdata/scripts/userdata.final.sh:114
Warn: downloadThenRun not pinned by hash: lib/backend/iaas/userdata/scripts/userdata.final.sh:127
Warn: downloadThenRun not pinned by hash: lib/backend/iaas/userdata/scripts/userdata.netsec.sh:1328
Warn: downloadThenRun not pinned by hash: lib/backend/iaas/userdata/scripts/userdata.netsec.sh:1341
Info: 0 out of 32 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 7 third-party GitHubAction dependencies pinned
Info: 0 out of 16 containerImage dependencies pinned
Info: 0 out of 8 downloadThenRun dependencies pinned