Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy-documentation.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/deploy-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy-documentation.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/deploy-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy-documentation.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/deploy-documentation.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy-documentation.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/deploy-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/new-linter-checklist.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/new-linter-checklist.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/post-release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-release.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-release.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/post-release.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-documentation.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-documentation.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-documentation.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: build/buildx-alpine.Dockerfile:2: pin your Docker image by updating golang:1.24-alpine to golang:1.24-alpine@sha256:7772cb5322baa875edd74705556d08f0eeca7b9c4b5367754ce3f2f00041ccee
Warn: containerImage not pinned by hash: build/buildx.Dockerfile:2: pin your Docker image by updating golang:1.24 to golang:1.24@sha256:d9db32125db0c3a680cfb7a1afcaefb89c898a075ec148fdc2f0f646cc2ed509
Warn: downloadThenRun not pinned by hash: scripts/bench/bench_local.sh:36
Warn: downloadThenRun not pinned by hash: scripts/bench/bench_version.sh:40
Warn: npmCommand not pinned by hash: .github/workflows/deploy-documentation.yml:36
Warn: downloadThenRun not pinned by hash: .github/workflows/post-release.yml:78
Warn: npmCommand not pinned by hash: .github/workflows/pr-documentation.yml:35
Info: 0 out of 31 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 8 third-party GitHubAction dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned
Info: 0 out of 3 downloadThenRun dependencies pinned
Info: 0 out of 2 npmCommand dependencies pinned