Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/audits.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/audits.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/audits.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/audits.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:123: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:195: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:201: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:205: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:208: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:271: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-tags.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/check-tags.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-coverage.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/code-coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-coverage.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/code-coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-coverage.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/code-coverage.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/code-coverage.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/code-coverage.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/code-coverage.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/code-coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-coverage.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/code-coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy-website.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/deploy-website.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy-website.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/deploy-website.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy-website.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/deploy-website.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy-website.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/deploy-website.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy-website.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/deploy-website.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy-website.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/deploy-website.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dispatch.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/dispatch.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:267: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:305: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:343: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:365: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:377: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:403: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:415: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:433: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:436: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:439: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:447: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:452: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:164: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:178: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:199: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:207: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:219: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:222: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:229: update your workflow using https://app.stepsecurity.io/secureworkflow/spinframework/spin/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:5
Warn: containerImage not pinned by hash: .github/Dockerfile:1: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:6ac2c08566499cc2415926653cf2ed7c3aedac445675a013cc09469c9e118fdd
Warn: containerImage not pinned by hash: .github/distroless.Dockerfile:1: pin your Docker image by updating gcr.io/distroless/static-debian12 to gcr.io/distroless/static-debian12@sha256:b7b9a6953e7bed6baaf37329331051d7bdc1b99c885f6dbeb72d75b1baad54f9
Warn: goCommand not pinned by hash: .devcontainer/Dockerfile:21
Warn: npmCommand not pinned by hash: .devcontainer/Dockerfile:34
Info: 0 out of 36 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 18 third-party GitHubAction dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 1 out of 4 containerImage dependencies pinned