Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:278: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:295: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:300: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:330: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:358: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:375: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:380: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:410: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:473: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:612: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:631: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:650: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/build.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/docker.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/lint.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/lint.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/linux.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/linux.yml/dev-next?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/linux.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/linux.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/linux.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux.yml:178: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/linux.yml/dev-next?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/SagerNet/sing-box/stale.yml/dev-next?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:20
Info: 11 out of 32 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 12 third-party GitHubAction dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned
Info: 6 out of 6 goCommand dependencies pinned