Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy-documentation.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/deploy-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy-documentation.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/deploy-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy-documentation.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/deploy-documentation.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy-documentation.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/deploy-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/new-linter-checklist.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/new-linter-checklist.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/post-release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-release.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-release.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/post-release.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-checks.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-documentation.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-documentation.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-documentation.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-tests.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/pr-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/golangci/golangci-lint/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: build/buildx-alpine.Dockerfile:2: pin your Docker image by updating golang:1.24-alpine to golang:1.24-alpine@sha256:ef18ee7117463ac1055f5a370ed18b8750f01589f13ea0b48642f5792b234044
Warn: containerImage not pinned by hash: build/buildx.Dockerfile:2: pin your Docker image by updating golang:1.24 to golang:1.24@sha256:39d9e7d9c5d9c9e4baf0d8fff579f06d5032c0f4425cdec9e86732e8e4e374dc
Warn: downloadThenRun not pinned by hash: scripts/bench/bench_local.sh:36
Warn: downloadThenRun not pinned by hash: scripts/bench/bench_version.sh:40
Warn: npmCommand not pinned by hash: .github/workflows/deploy-documentation.yml:36
Warn: downloadThenRun not pinned by hash: .github/workflows/post-release.yml:78
Warn: npmCommand not pinned by hash: .github/workflows/pr-documentation.yml:35
Info: 0 out of 31 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 8 third-party GitHubAction dependencies pinned
Info: 0 out of 3 downloadThenRun dependencies pinned
Info: 0 out of 2 npmCommand dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned