Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/benchmark.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/benchmark.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/docs.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-docs.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go-docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser-snapshot.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/goreleaser-snapshot.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser-snapshot.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/goreleaser-snapshot.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser-snapshot.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/goreleaser-snapshot.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/greeting.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/greeting.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tag.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/tag.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tag.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/tag.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tag.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/tag.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tag.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/tag.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tag.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/tag.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tag.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/tag.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tag.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/tag.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-woke-usage.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/update-woke-usage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-woke-usage.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/update-woke-usage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/woke.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/woke.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/woke.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/woke.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/woke.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/woke.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/woke.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/woke.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/woke.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/get-woke/woke/woke.yml/main?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:3
Warn: containerImage not pinned by hash: build/Dockerfile:1: pin your Docker image by updating alpine:3.12 to alpine:3.12@sha256:c75ac27b49326926b803b9ed43bf088bc220d22556de1bc5f72d742c91398f69
Warn: containerImage not pinned by hash: dev/Dockerfile:2: pin your Docker image by updating golang:1.18 to golang:1.18@sha256:50c889275d26f816b5314fc99f55425fa76b18fcaf16af255f5d57f09e1f48da
Warn: containerImage not pinned by hash: docs/Dockerfile:1: pin your Docker image by updating python:3-alpine to python:3-alpine@sha256:323a717dc4a010fee21e3f1aac738ee10bb485de4e7593ce242b36ee48d6b352
Warn: npmCommand not pinned by hash: .devcontainer/Dockerfile:18-23
Warn: pipCommand not pinned by hash: .devcontainer/Dockerfile:17-22
Warn: pipCommand not pinned by hash: docs/Dockerfile:5
Warn: pipCommand not pinned by hash: .devcontainer/scripts/docker-debian.sh:204
Warn: goCommand not pinned by hash: .devcontainer/scripts/install_go_dev_tools.sh:6
Warn: goCommand not pinned by hash: .devcontainer/scripts/install_go_dev_tools.sh:7
Warn: downloadThenRun not pinned by hash: .devcontainer/scripts/install_go_dev_tools.sh:8
Warn: downloadThenRun not pinned by hash: .github/workflows/benchmark.yml:25
Warn: pipCommand not pinned by hash: .github/workflows/docs.yml:25
Warn: downloadThenRun not pinned by hash: .github/workflows/go.yml:85
Info: 0 out of 29 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 9 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 4 pipCommand dependencies pinned
Info: 1 out of 3 goCommand dependencies pinned
Info: 0 out of 3 downloadThenRun dependencies pinned