Info: Possibly incomplete results: error parsing shell code: invalid parameter name: .github/workflows/release.yml:82
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bridge-ci.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-ci.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-ci.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-ci.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bridge-ci.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-ci.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bridge-ci.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-ci.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bridge-release.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-release.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bridge-release.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bridge-release.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-release.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-release.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-release.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-release.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bridge-security.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-security.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bridge-security.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/bridge-security.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-docker-release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-docker-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-docker-release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-docker-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-docker-release.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-docker-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-docker-release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-docker-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-docker-release.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-docker-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-lint.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-lint.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-lint.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-lint.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-lint.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-lint.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cli-security.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-security.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cli-security.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/cli-security.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codegen.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/codegen.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/csharp-lint.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/csharp-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/csharp-lint.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/csharp-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/csharp-release.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/csharp-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/csharp-release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/csharp-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-ci.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/go-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-ci.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/go-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-lint.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/go-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go-lint.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/go-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/java-lint.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/java-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/java-lint.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/java-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/java-release.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/java-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/java-release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/java-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/javascript-lint.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/javascript-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/javascript-lint.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/javascript-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/javascript-release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/javascript-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/javascript-release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/javascript-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/kotlin-lint.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/kotlin-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/kotlin-lint.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/kotlin-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/kotlin-release.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/kotlin-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/kotlin-release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/kotlin-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/php-ci.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/php-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/php-ci.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/php-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/python-lint.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/python-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/python-lint.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/python-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/python-release.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/python-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/python-release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/python-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/python-release.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/python-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/python-tests.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/python-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/python-tests.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/python-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:136: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:191: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:209: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:229: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:240: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:253: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:292: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:298: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:338: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ruby-lint.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/ruby-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ruby-lint.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/ruby-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ruby-release.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/ruby-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ruby-release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/ruby-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rust-lint.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust-lint.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rust-lint.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust-lint.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rust-lint.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust-lint.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust-lint.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust-lint.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rust-release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust-release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust-release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rust-security.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-security.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rust-security.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/rust-security.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-ci.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-ci.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-ci.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-ci.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-ci.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-ci.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-ci.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-docker-image.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-docker-image.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-release.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-release.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-release.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-release.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-release.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/server-security.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-security.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/server-security.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/server-security.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/typos.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/typos.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/typos.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/typos.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-postman.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/svix/svix-webhooks/update-postman.yml/main?enable=pin
Warn: containerImage not pinned by hash: bridge/Dockerfile:2
Warn: containerImage not pinned by hash: bridge/Dockerfile:52
Warn: containerImage not pinned by hash: server/Dockerfile:4
Warn: containerImage not pinned by hash: server/Dockerfile:9
Warn: containerImage not pinned by hash: server/Dockerfile:14
Warn: containerImage not pinned by hash: server/Dockerfile:41
Warn: containerImage not pinned by hash: svix-cli/Dockerfile:2
Warn: containerImage not pinned by hash: svix-cli/Dockerfile:40
Warn: nugetCommand not pinned by hash: .github/workflows/csharp-lint.yml:33: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/csharp-release.yml:28: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: pipCommand not pinned by hash: .github/workflows/python-lint.yml:29
Warn: pipCommand not pinned by hash: .github/workflows/python-lint.yml:30
Warn: pipCommand not pinned by hash: .github/workflows/python-lint.yml:31
Warn: pipCommand not pinned by hash: .github/workflows/python-release.yml:28
Warn: pipCommand not pinned by hash: .github/workflows/python-release.yml:29
Warn: pipCommand not pinned by hash: .github/workflows/python-release.yml:34
Warn: pipCommand not pinned by hash: .github/workflows/python-tests.yml:34
Warn: pipCommand not pinned by hash: .github/workflows/python-tests.yml:35
Warn: pipCommand not pinned by hash: .github/workflows/python-tests.yml:36
Warn: downloadThenRun not pinned by hash: .github/workflows/release.yml:71
Warn: downloadThenRun not pinned by hash: .github/workflows/release.yml:129
Info: 0 out of 73 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 46 third-party GitHubAction dependencies pinned
Info: 0 out of 8 containerImage dependencies pinned
Info: 0 out of 2 nugetCommand dependencies pinned
Info: 1 out of 1 goCommand dependencies pinned
Info: 0 out of 9 pipCommand dependencies pinned
Info: 0 out of 2 downloadThenRun dependencies pinned