Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-docker-proto-image.yaml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/build-docker-proto-image.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-docker-proto-image.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/build-docker-proto-image.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-docker-proto-image.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/build-docker-proto-image.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-docker-proto-image.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/build-docker-proto-image.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:147: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:162: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:172: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:223: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:252: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:263: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:273: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:283: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:293: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:303: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:313: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:323: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:333: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:343: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:353: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:363: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-tag.yaml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci-tag.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:160: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:170: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:198: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:204: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:221: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:250: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:261: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:271: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:281: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:291: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:301: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:311: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:321: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:331: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:341: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:351: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:361: update your workflow using https://app.stepsecurity.io/secureworkflow/harmony-one/harmony/ci.yaml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:ed1544e454989078f5dec1bfdabd8c5cc9c48e0705d07b678ab6ae3fb61952d2
Warn: containerImage not pinned by hash: api/service/legacysync/downloader/Proto.Dockerfile:1: pin your Docker image by updating golang:1.22.5-bullseye to golang:1.22.5-bullseye@sha256:583d5af8289d30de50aa0dcf4985d8b8746e52622becd6e1a62cfe191d5275a5
Warn: containerImage not pinned by hash: rosetta/infra/Dockerfile:2
Warn: containerImage not pinned by hash: rosetta/infra/Dockerfile:35: pin your Docker image by updating ubuntu:20.04 to ubuntu:20.04@sha256:8e5c4f0285ecbb4ead070431d29b576a530d3166df73ec44affc1cd27555141b
Warn: containerImage not pinned by hash: scripts/docker/Dockerfile:5
Warn: containerImage not pinned by hash: scripts/docker/Dockerfile:33: pin your Docker image by updating alpine:3.16.0 to alpine:3.16.0@sha256:686d8c9dfa6f3ccfc8230bc3178d23f84eeaf7e457f36f271ab1acc53015037c
Warn: goCommand not pinned by hash: Dockerfile:51-59
Warn: goCommand not pinned by hash: Dockerfile:51-59
Warn: goCommand not pinned by hash: Dockerfile:51-59
Warn: goCommand not pinned by hash: Dockerfile:51-59
Warn: goCommand not pinned by hash: Dockerfile:51-59
Warn: goCommand not pinned by hash: Dockerfile:51-59
Warn: goCommand not pinned by hash: Dockerfile:51-59
Warn: goCommand not pinned by hash: Dockerfile:51-59
Warn: goCommand not pinned by hash: api/service/legacysync/downloader/Proto.Dockerfile:7
Info: 0 out of 47 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 13 third-party GitHubAction dependencies pinned
Info: 2 out of 11 goCommand dependencies pinned
Info: 0 out of 6 containerImage dependencies pinned