Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:318: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:387: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/enos-lint.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/enos-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/enos-lint.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/enos-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/enos-lint.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/enos-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/enos-release-testing-oss.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/enos-release-testing-oss.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-ci-bootstrap.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-ci-bootstrap.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-enos-scenario-ui.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-enos-scenario-ui.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-enos-scenario-ui.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-enos-scenario-ui.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-go.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-go.yml:295: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-containers.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-containers.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-containers.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-containers.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-containers.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-containers.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-matrix.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-matrix.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-matrix.yml:207: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-matrix.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-matrix.yml:220: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-matrix.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-matrix.yml:293: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-matrix.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-matrix.yml:300: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-matrix.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-matrix.yml:307: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-matrix.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario-matrix.yml:314: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario-matrix.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-run-enos-scenario.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/hashicorp/vault/test-run-enos-scenario.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:5
Warn: containerImage not pinned by hash: Dockerfile:82
Warn: containerImage not pinned by hash: Dockerfile:175
Warn: containerImage not pinned by hash: Dockerfile:177
Warn: containerImage not pinned by hash: Dockerfile:179
Warn: containerImage not pinned by hash: scripts/cross/Dockerfile:4: pin your Docker image by updating debian:buster to debian:buster@sha256:58ce6f1271ae1c8a2006ff7d3e54e9874d839f573d8009c20154ad0f2fb0a225
Warn: containerImage not pinned by hash: scripts/docker/Dockerfile:8
Warn: containerImage not pinned by hash: scripts/docker/Dockerfile:21: pin your Docker image by updating alpine:3.13 to alpine:3.13@sha256:469b6e04ee185740477efa44ed5bdd64a07bbdd6c7e5f5d169e540889597b911
Warn: containerImage not pinned by hash: scripts/docker/Dockerfile.ui:3
Warn: containerImage not pinned by hash: scripts/docker/Dockerfile.ui:44: pin your Docker image by updating alpine:3.13 to alpine:3.13@sha256:469b6e04ee185740477efa44ed5bdd64a07bbdd6c7e5f5d169e540889597b911
Warn: containerImage not pinned by hash: website/Dockerfile:4: pin your Docker image by updating docker.mirror.hashicorp.services/node:18.18.2-alpine to docker.mirror.hashicorp.services/node:18.18.2-alpine@sha256:16b46e5ea9fb5c2d13dda36f0feb670fa89de6a412725007555f2eee9a126b60
Warn: downloadThenRun not pinned by hash: scripts/cross/Dockerfile:18
Warn: goCommand not pinned by hash: scripts/cross/Dockerfile:36
Warn: downloadThenRun not pinned by hash: scripts/docker/Dockerfile.ui:22
Warn: npmCommand not pinned by hash: website/Dockerfile:10
Warn: npmCommand not pinned by hash: website/Dockerfile:11
Warn: npmCommand not pinned by hash: enos/modules/build_local/scripts/build.sh:8
Warn: npmCommand not pinned by hash: .github/workflows/ci.yml:235
Warn: pipCommand not pinned by hash: .github/workflows/security-scan.yml:62
Info: 72 out of 72 GitHub-owned GitHubAction dependencies pinned
Info: 21 out of 45 third-party GitHubAction dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned
Info: 0 out of 4 npmCommand dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 11 containerImage dependencies pinned
Info: 0 out of 2 downloadThenRun dependencies pinned