Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto_aur_release_stable.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/auto_aur_release_stable.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd.yml:144: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:149: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd.yml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd.yml:172: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:189: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:199: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:204: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cd.yml:209: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cd.yml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/cd.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dockerimage.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/dockerimage.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerimage.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/dockerimage.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerimage.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/dockerimage.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerimage.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/dockerimage.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerimage.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/dockerimage.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dockerimage.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/dockerimage.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/target-branch.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/siyuan-note/siyuan/target-branch.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:21
Warn: containerImage not pinned by hash: Dockerfile:37: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: npmCommand not pinned by hash: Dockerfile:7-16
Warn: npmCommand not pinned by hash: Dockerfile:7-16
Warn: pipCommand not pinned by hash: .github/workflows/cd.yml:34
Warn: goCommand not pinned by hash: .github/workflows/cd.yml:162
Warn: goCommand not pinned by hash: .github/workflows/cd.yml:162
Warn: npmCommand not pinned by hash: .github/workflows/cd.yml:178
Info: 0 out of 7 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 18 third-party GitHubAction dependencies pinned
Info: 0 out of 3 containerImage dependencies pinned
Info: 0 out of 3 npmCommand dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 2 goCommand dependencies pinned