Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/install-test.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/install-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/install-test.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/install-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/install-test.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/install-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/install-test.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/install-test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/install-test.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/install-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/install-test.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/install-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-snapshot.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/test-snapshot.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-snapshot.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/test-snapshot.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-snapshot.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/test-snapshot.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-snapshot.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/test-snapshot.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/stripe/stripe-cli/test.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: goCommand not pinned by hash: .github/workflows/test.yml:33
Warn: goCommand not pinned by hash: .github/workflows/test.yml:34
Info: 0 out of 16 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 9 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 1 out of 3 goCommand dependencies pinned