Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/br_compatible_test.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/br_compatible_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/br_compatible_test.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/br_compatible_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/br_compatible_test.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/br_compatible_test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bug-closed.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/bug-closed.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bug-closed.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/bug-closed.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compile_br.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/compile_br.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compile_br.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/compile_br.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compile_br.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/compile_br.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compile_br.yaml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/compile_br.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compile_br.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/compile_br.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compile_br.yaml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/compile_br.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dumpling_integration_test.yml:162: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/dumpling_integration_test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labeler.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/labeler.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/license-checker.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/license-checker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/license-checker.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/dragonly/tidb/license-checker.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:16
Warn: containerImage not pinned by hash: Dockerfile:43: pin your Docker image by updating alpine to alpine@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: br/docker/Dockerfile:2
Warn: containerImage not pinned by hash: br/docker/Dockerfile:9
Warn: containerImage not pinned by hash: br/docker/Dockerfile:11: pin your Docker image by updating golang:1.16.4-buster to golang:1.16.4-buster@sha256:fc58cc5aaeb7fe258a7d31450e8d0480dd2cb07e4c6fd9bf2a09b464ce0e379c
Info: 0 out of 21 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 8 third-party GitHubAction dependencies pinned
Info: 0 out of 5 containerImage dependencies pinned