Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/closed_references.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/closed_references.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/closed_references.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/closed_references.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/closed_references.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/closed_references.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/conventional_commits.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/conventional_commits.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/conventional_commits.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/conventional_commits.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/conventional_commits.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/conventional_commits.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cve-scan.yaml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/cve-scan.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/format.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/format.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/format.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/format.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labels.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/labels.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labels.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/labels.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/licenses.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/licenses.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/licenses.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/licenses.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/licenses.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/licenses.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/milestone.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/milestone.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/milestone.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/milestone.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/milestone.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/milestone.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pm.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/pm.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/oathkeeper/stale.yml/master?enable=pin
Warn: containerImage not pinned by hash: .docker/Dockerfile-alpine:1: pin your Docker image by updating alpine:3.21.2 to alpine:3.21.2@sha256:56fa17d2a7e7f168a043a2712e63aed1f8543aeafdcee47c58dcffe38ed51099
Warn: containerImage not pinned by hash: .docker/Dockerfile-build:2
Warn: containerImage not pinned by hash: .docker/Dockerfile-build:22
Warn: containerImage not pinned by hash: .docker/Dockerfile-distroless-static:1: pin your Docker image by updating gcr.io/distroless/static-debian12:nonroot to gcr.io/distroless/static-debian12:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:59
Info: 0 out of 18 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 31 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned