Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): Makefile:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/create-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/create-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labeler.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/labeler.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/nightly.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/nightly.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/nightly.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/nightly.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/publish-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/publish-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/publish-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/publish-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-release.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/publish-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-release.yml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/publish-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-release.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/publish-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/oauth2-proxy/oauth2-proxy/stale.yml/master?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:1: pin your Docker image by updating mcr.microsoft.com/vscode/devcontainers/go:1-1.23 to mcr.microsoft.com/vscode/devcontainers/go:1-1.23@sha256:f12d68fb2acd19b5b7a5833ab39e0ff1c16646f698713e3661fce0cb6cb3b590
Warn: containerImage not pinned by hash: Dockerfile:15
Warn: containerImage not pinned by hash: Dockerfile:59
Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:30
Warn: npmCommand not pinned by hash: .github/workflows/create-release.yml:69
Warn: npmCommand not pinned by hash: .github/workflows/docs.yml:31
Warn: npmCommand not pinned by hash: .github/workflows/docs.yml:48
Warn: downloadThenRun not pinned by hash: .github/workflows/publish-release.yml:55
Info: 0 out of 23 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 8 third-party GitHubAction dependencies pinned
Info: 0 out of 3 containerImage dependencies pinned
Info: 0 out of 2 downloadThenRun dependencies pinned
Info: 0 out of 3 npmCommand dependencies pinned