Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/auto-assign-issue.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/auto-assign-issue.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/auto-gh-pr.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/auto-gh-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto-invite.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/auto-invite.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto-invite.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/auto-invite.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/auto-tag.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/auto-tag.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bot-auto-cherry-pick.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/bot-auto-cherry-pick.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bot-cherry-pick.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/bot-cherry-pick.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bot-cherry-pick.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/bot-cherry-pick.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cla.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/cla.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-language-detector.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/code-language-detector.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/code-language-detector.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/code-language-detector.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-typecheck.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/go-typecheck.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go-typecheck.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/go-typecheck.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/golangci-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gosec.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/gosec.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gosec.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/gosec.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/link-pr.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/link-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/link-pr.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/link-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/link-pr.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/link-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lock-issue.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/lock-issue.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/milestone.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/milestone.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/openimci.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/openimci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/openimci.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/openimci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/openimci.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/openimci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/project-progress.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/project-progress.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/pull-request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/pull-request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/pull-request.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull-request.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/pull-request.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-drafter.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/openimsdk/tools/release-drafter.yml/main?enable=pin
Warn: goCommand not pinned by hash: utils/mageutil/usage-guide/bootstrap.sh:12
Info: 0 out of 17 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 15 third-party GitHubAction dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned