Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aws-e2e.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/aws-e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aws-e2e.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/aws-e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aws-e2e.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/aws-e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/aws-e2e.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/aws-e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aws-e2e.yaml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/aws-e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-test.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/cli-test.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-test.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/cli-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-test.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/cli-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-test.yaml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/cli-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-test.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/cli-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-run-test.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-run-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-run-test.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-run-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-run-test.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-run-test.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dashboard-run-test.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-run-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-run-test.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-run-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-run-test.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-run-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-start-test.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-start-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-start-test.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-start-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-start-test.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-start-test.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dashboard-start-test.yaml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-start-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-start-test.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-start-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dashboard-start-test.yaml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/dashboard-start-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/publish.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/publish.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/publish.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/nitrictech/cli/release.yaml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:21: pin your Docker image by updating python:3.9-slim to python:3.9-slim@sha256:caaf1af9e23adc6149e5d20662b267ead9505868ff07c7673dc4a7166951cfea
Warn: containerImage not pinned by hash: pkg/collector/default-migrations.dockerfile:2: pin your Docker image by updating migrate/migrate to migrate/migrate@sha256:f21c436af23c282f4516b00ba3e93bccf5c5fe5cd52530fd5c319a936998f539
Warn: containerImage not pinned by hash: pkg/project/runtime/csharp.dockerfile:1
Warn: containerImage not pinned by hash: pkg/project/runtime/csharp.dockerfile:17: pin your Docker image by updating mcr.microsoft.com/dotnet/runtime-deps:8.0 to mcr.microsoft.com/dotnet/runtime-deps:8.0@sha256:74a14ce3ebbb56752032d643754dd0509da15418f2eea1526241b8e104114021
Warn: containerImage not pinned by hash: pkg/project/runtime/dart.dockerfile:1
Warn: containerImage not pinned by hash: pkg/project/runtime/dart.dockerfile:21: pin your Docker image by updating alpine to alpine@sha256:56fa17d2a7e7f168a043a2712e63aed1f8543aeafdcee47c58dcffe38ed51099
Warn: containerImage not pinned by hash: pkg/project/runtime/javascript.dockerfile:2: pin your Docker image by updating node:22.4.1-alpine to node:22.4.1-alpine@sha256:ba898e86c2cc720c8cf2ae05f8d2d4697fe0c8ca3e920d6fbf14a6cbf50bb9ca
Warn: containerImage not pinned by hash: pkg/project/runtime/jvm.dockerfile:2: pin your Docker image by updating openjdk:22-slim to openjdk:22-slim@sha256:5a6e9da3cdeaa179421f7ad98b32af0e52b6ef46261e3bf090d7e2f72e6df766
Warn: containerImage not pinned by hash: pkg/project/runtime/python.dockerfile:1: pin your Docker image by updating python:3.11-slim to python:3.11-slim@sha256:873952659a04188d2a62d5f7e30fd673d2559432a847a8ad5fcaf9cbd085e9ed
Warn: containerImage not pinned by hash: pkg/project/runtime/typescript.dockerfile:2
Warn: containerImage not pinned by hash: pkg/project/runtime/typescript.dockerfile:31
Warn: downloadThenRun not pinned by hash: Dockerfile:5-11
Warn: downloadThenRun not pinned by hash: Dockerfile:69-70
Warn: pipCommand not pinned by hash: pkg/project/runtime/python.dockerfile:12
Warn: pipCommand not pinned by hash: pkg/project/runtime/python.dockerfile:22
Info: 0 out of 21 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 2 pipCommand dependencies pinned
Info: 0 out of 12 containerImage dependencies pinned
Info: 0 out of 2 downloadThenRun dependencies pinned