Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto_label_issues.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/auto_label_issues.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-and-publish-release.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-and-publish-release.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-release.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-and-publish-release.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-release.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-and-publish-release.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-and-publish-release.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-and-publish-release.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-release.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-and-publish-release.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-publish-release.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-and-publish-release.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-test.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-test.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-test.yaml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-test.yaml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/build-test.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/label-comments.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/label-comments.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/label-comments.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/label-comments.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/label-comments.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/label-comments.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/label-comments.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/label-comments.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sonar.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/sonar.yaml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sonar.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/sonar.yaml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sonar.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/sonar.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sonar.yaml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/sonar.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sonar.yaml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/sonar.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sonar.yaml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/sonar.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sonar.yaml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/sonar.yaml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sonar.yaml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/sonar.yaml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/opencost/opencost/stale.yml/develop?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:35: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: Dockerfile.cross:1: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: Dockerfile.debug:2: pin your Docker image by updating golang:alpine to golang:alpine@sha256:43c094ad24b6ac0546c62193baeb3e6e49ce14d3250845d166c77c25f64b0386
Warn: goCommand not pinned by hash: Dockerfile.debug:16
Warn: goCommand not pinned by hash: .github/workflows/build-test.yaml:36
Info: 0 out of 11 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 18 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 1 out of 3 goCommand dependencies pinned