Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/build-test.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/build-test.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-test.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/build-test.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/codeql-analysis.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/codeql-analysis.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/codeql-analysis.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/codeql-analysis.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dep-auto-merge.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/dep-auto-merge.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dep-auto-merge.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/dep-auto-merge.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dockerhub-push.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/dockerhub-push.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerhub-push.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/dockerhub-push.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerhub-push.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/dockerhub-push.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerhub-push.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/dockerhub-push.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerhub-push.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/dockerhub-push.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint-test.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/lint-test.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint-test.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/lint-test.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-test.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/lint-test.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-binary.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/release-binary.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-binary.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/release-binary.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-binary.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/release-binary.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-test.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/release-test.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-test.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/release-test.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/projectdiscovery/subfinder/release-test.yml/dev?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:2
Warn: containerImage not pinned by hash: Dockerfile:11: pin your Docker image by updating alpine:3.18.6 to alpine:3.18.6@sha256:11e21d7b981a59554b3f822c49f6e9f57b6068bb74f49c4cd5cc4c663c7e5160
Info: 0 out of 14 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 9 third-party GitHubAction dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned