Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-interop-docker.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/build-interop-docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-interop-docker.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/build-interop-docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-interop-docker.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/build-interop-docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-interop-docker.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/build-interop-docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-interop-docker.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/build-interop-docker.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/clusterfuzz-lite-pr.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/clusterfuzz-lite-pr.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/clusterfuzz-lite-pr.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/clusterfuzz-lite-pr.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cross-compile.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/cross-compile.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cross-compile.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/cross-compile.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/integration.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/integration.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:8: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/lint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/unit.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/unit.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/unit.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/unit.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/unit.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/quic-go/quic-go/unit.yml/master?enable=pin
Warn: containerImage not pinned by hash: .clusterfuzzlite/Dockerfile:1: pin your Docker image by updating gcr.io/oss-fuzz-base/base-builder-go:v1 to gcr.io/oss-fuzz-base/base-builder-go:v1@sha256:84e808d813f6718c7061e165dd9b20d0d348884433deea7bcdaf210ac00dfb24
Warn: containerImage not pinned by hash: interop/Dockerfile:1
Warn: containerImage not pinned by hash: interop/Dockerfile:29: pin your Docker image by updating martenseemann/quic-network-simulator-endpoint:latest to martenseemann/quic-network-simulator-endpoint:latest@sha256:3c373d0bac88ac0a005c56628e551fe980e44bf2dd50b9c6904d58d7f8d54089
Info: 0 out of 12 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 14 third-party GitHubAction dependencies pinned
Info: 0 out of 3 containerImage dependencies pinned
Info: 2 out of 2 goCommand dependencies pinned