Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/publish.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/publish.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/publish.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/publish.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/publish.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/publish.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/publish.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/report.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/report.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/report.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/report.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/report.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/report.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/shellcheck.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/shellcheck.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/shellcheck.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/shellcheck.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/neicnordic/sda-download/test.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: pipCommand not pinned by hash: .github/integration/setup/common/20_tools.sh:3
Warn: pipCommand not pinned by hash: .github/integration/setup/s3/100_s3_storage_setup.sh:3
Warn: pipCommand not pinned by hash: .github/integration/setup/s3notls/99_s3_storage_setup.sh:3
Warn: downloadThenRun not pinned by hash: .github/workflows/test.yml:31
Info: 0 out of 13 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 8 third-party GitHubAction dependencies pinned
Info: 1 out of 1 goCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 0 out of 3 pipCommand dependencies pinned