Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:324: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:327: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:388: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:391: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:487: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/development.yml:532: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:581: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:596: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:602: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:612: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:615: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/development.yml:617: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/development.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/development.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/development.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/development.yml:251: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:276: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:283: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:290: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/development.yml:314: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/development.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:144: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:147: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:151: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:235: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:284: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:291: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:329: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:382: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:431: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:449: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:456: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:475: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:480: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:485: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:490: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:513: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:525: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:536: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:541: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:546: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:551: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:556: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:561: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:566: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:571: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:576: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:581: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:586: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:591: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:596: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:601: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:606: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:611: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:616: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:621: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:626: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:631: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:201: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:208: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:215: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:222: update your workflow using https://app.stepsecurity.io/secureworkflow/drakkan/sftpgo/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:33: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:1209d8fd77def86ceb6663deef7956481cc6c14a25e1e64daec12c0ceffcc19d
Warn: containerImage not pinned by hash: Dockerfile.alpine:1
Warn: containerImage not pinned by hash: Dockerfile.alpine:28: pin your Docker image by updating alpine:3.21 to alpine:3.21@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: Dockerfile.distroless:1
Warn: containerImage not pinned by hash: Dockerfile.distroless:35: pin your Docker image by updating gcr.io/distroless/static-debian12 to gcr.io/distroless/static-debian12@sha256:3d0f463de06b7ddff27684ec3bfd0b54a425149d0f8685308b1fdf297b0265e9
Info: 0 out of 68 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 15 third-party GitHubAction dependencies pinned
Info: 0 out of 6 containerImage dependencies pinned