Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/benchmark.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/benchmark.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/benchmark.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmark.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/benchmark.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmark.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/benchmark.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-test.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/release-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-test.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/release-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-test.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/release-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-test.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/release-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-test.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/release-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-test.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/release-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-test.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/release-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-test.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/release-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tagpr.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tagpr.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tagpr.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tagpr.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tagpr.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/runn/tagpr.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:12: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:12c396bd585df7ec21d5679bb6a83d4878bc4415ce926c9e5ea6426d23c60bdc
Warn: containerImage not pinned by hash: Dockerfile.slim:1
Warn: containerImage not pinned by hash: Dockerfile.slim:12: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:12c396bd585df7ec21d5679bb6a83d4878bc4415ce926c9e5ea6426d23c60bdc
Info: 0 out of 18 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 20 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned