Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-check.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-check.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-check.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-check.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-check.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-image.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-image.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:160: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-image.yml:186: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/docker-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:136: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:202: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:217: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:223: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gateway-conformance.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gateway-conformance.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generated-pr.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/generated-pr.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gobuild.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gobuild.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gobuild.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gobuild.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golang-analysis.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/golang-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golang-analysis.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/golang-analysis.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golang-analysis.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/golang-analysis.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golang-analysis.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/golang-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golint.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/golint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golint.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/golint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gotest.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gotest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gotest.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gotest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gotest.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gotest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gotest.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gotest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gotest.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gotest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gotest.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gotest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gotest.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/gotest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/interop.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/interop.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sharness.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sharness.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sharness.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sharness.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sharness.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sharness.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sharness.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sharness.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sharness.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sharness.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/spellcheck.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/spellcheck.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/stale.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/stale.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sync-release-assets.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sync-release-assets.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sync-release-assets.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sync-release-assets.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-release-assets.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sync-release-assets.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-release-assets.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/sync-release-assets.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-migrations.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/test-migrations.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-migrations.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/test-migrations.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-migrations.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/ipfs/kubo/test-migrations.yml/master?enable=pin
Warn: containerImage not pinned by hash: .github/legacy/Dockerfile.goipfs-stub:4: pin your Docker image by updating busybox:stable-glibc to busybox:stable-glibc@sha256:8fe66e6f43e59abc326f16fa4491708d15591c42a17486235e55fabf18ba5cb6
Warn: containerImage not pinned by hash: Dockerfile:3: pin your Docker image by updating golang:1.25 to golang:1.25@sha256:6bac879c5b77e0fc9c556a5ed8920e89dab1709bd510a854903509c828f67f96
Warn: containerImage not pinned by hash: Dockerfile:34: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:78d2f66e0fec9e5a39fb2c72ea5e052b548df75602b5215ed01a17171529f706
Warn: containerImage not pinned by hash: Dockerfile:52: pin your Docker image by updating busybox:stable-glibc to busybox:stable-glibc@sha256:8fe66e6f43e59abc326f16fa4491708d15591c42a17486235e55fabf18ba5cb6
Warn: containerImage not pinned by hash: test/3nodetest/bootstrap/Dockerfile:1
Warn: containerImage not pinned by hash: test/3nodetest/client/Dockerfile:1
Warn: containerImage not pinned by hash: test/3nodetest/data/Dockerfile:1: pin your Docker image by updating ubuntu to ubuntu@sha256:66460d557b25769b102175144d538d88219c077c678a49af4afca6fbfc1b5252
Warn: containerImage not pinned by hash: test/3nodetest/server/Dockerfile:1
Info:   0 out of  47 GitHub-owned GitHubAction dependencies pinned
Info:   2 out of  34 third-party GitHubAction dependencies pinned
Info:   0 out of   8 containerImage dependencies pinned
Info:   1 out of   1 npmCommand dependencies pinned