Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-pulse.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/build-pulse.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-pulse.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/build-pulse.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-pulse.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/build-pulse.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/builtin-actor-tests.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/builtin-actor-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/builtin-actor-tests.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/builtin-actor-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release-issue.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/create-release-issue.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dependency-check.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/dependency-check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/docker.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-title-check.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/pr-title-check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:136: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:176: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:165: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-test.yml:227: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/reusable-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/stale.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:161: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:214: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/very-expensive-test.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/filecoin-project/lotus/very-expensive-test.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:2
Warn: containerImage not pinned by hash: Dockerfile:49
Warn: containerImage not pinned by hash: Dockerfile:68
Warn: containerImage not pinned by hash: Dockerfile:96
Warn: containerImage not pinned by hash: tools/dockers/docker-examples/basic-miner-busybox/Dockerfile:1: pin your Docker image by updating golang:1.14.1-buster to golang:1.14.1-buster@sha256:9d67058156a82fb59df9a734e3e9df6bfc73413bd4d5e279bbea4cdd04357f4c
Warn: containerImage not pinned by hash: tools/dockers/docker-examples/basic-miner-busybox/Dockerfile:55: pin your Docker image by updating busybox:1-glibc to busybox:1-glibc@sha256:210ce53959959e79523b8cb0f0bb1cf1c49bf9747cdedb47db1cf0db8e642f61
Warn: downloadThenRun not pinned by hash: tools/dockers/docker-examples/basic-miner-busybox/Dockerfile:8
Warn: goCommand not pinned by hash: .github/workflows/reusable-test.yml:138
Warn: goCommand not pinned by hash: .github/workflows/test.yml:141
Info: 0 out of 47 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 6 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 1 out of 3 goCommand dependencies pinned