Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-push.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-push.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-push.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-push.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-push.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-push.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-push.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-tests.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-tests.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-tests.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-tests.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/docker-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser-run.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/goreleaser-run.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser-run.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/goreleaser-run.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser-run.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/goreleaser-run.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser-test.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/goreleaser-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser-test.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/goreleaser-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser-test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/goreleaser-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/main.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/main.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:182: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/fsouza/fake-gcs-server/main.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:5
Warn: containerImage not pinned by hash: Dockerfile:13: pin your Docker image by updating alpine:3.21.2 to alpine:3.21.2@sha256:56fa17d2a7e7f168a043a2712e63aed1f8543aeafdcee47c58dcffe38ed51099
Warn: pipCommand not pinned by hash: ci/run-gsutil-example.sh:9
Warn: pipCommand not pinned by hash: ci/run-python-example.sh:10
Warn: goCommand not pinned by hash: .github/workflows/main.yml:87
Info: 0 out of 19 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 12 third-party GitHubAction dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned
Info: 0 out of 2 pipCommand dependencies pinned
Info: 1 out of 1 npmCommand dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned