Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/browserslist.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/browserslist.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/browserslist.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/browserslist.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/codeql.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-automerge.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/dependabot-automerge.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/staticcheck.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/taskcluster/taskcluster/staticcheck.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:4
Warn: containerImage not pinned by hash: Dockerfile:65
Warn: containerImage not pinned by hash: generic-worker.Dockerfile:3
Warn: containerImage not pinned by hash: generic-worker.Dockerfile:31: pin your Docker image by updating ubuntu:jammy to ubuntu:jammy@sha256:ed1544e454989078f5dec1bfdabd8c5cc9c48e0705d07b678ab6ae3fb61952d2
Warn: containerImage not pinned by hash: taskcluster/docker/browser-test/Dockerfile:1: pin your Docker image by updating node:22.14.0-bookworm to node:22.14.0-bookworm@sha256:c7fd844945a76eeaa83cb372e4d289b4a30b478a1c80e16c685b62c54156285b
Warn: containerImage not pinned by hash: taskcluster/docker/ci/Dockerfile:1
Warn: containerImage not pinned by hash: taskcluster/docker/ci/Dockerfile:2: pin your Docker image by updating node:22.14.0-bookworm to node:22.14.0-bookworm@sha256:c7fd844945a76eeaa83cb372e4d289b4a30b478a1c80e16c685b62c54156285b
Warn: containerImage not pinned by hash: taskcluster/docker/rabbit-test/Dockerfile:1: pin your Docker image by updating node:22.14.0-bookworm to node:22.14.0-bookworm@sha256:c7fd844945a76eeaa83cb372e4d289b4a30b478a1c80e16c685b62c54156285b
Warn: containerImage not pinned by hash: ui/Dockerfile:1: pin your Docker image by updating node:22.14.0 to node:22.14.0@sha256:c7fd844945a76eeaa83cb372e4d289b4a30b478a1c80e16c685b62c54156285b
Warn: containerImage not pinned by hash: workers/docker-worker/Dockerfile:1: pin your Docker image by updating lightsofapollo/ubuntu-node:unstable to lightsofapollo/ubuntu-node:unstable@sha256:bd4fa3f554e4ffa13d53185ee3217ba029af2d91f6afcd74d82ea480b3e71c20
Warn: containerImage not pinned by hash: workers/docker-worker/test/images/dind-test/Dockerfile:1: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: workers/docker-worker/test/images/test/Dockerfile:1: pin your Docker image by updating node:22.14.0 to node:22.14.0@sha256:c7fd844945a76eeaa83cb372e4d289b4a30b478a1c80e16c685b62c54156285b
Warn: downloadThenRun not pinned by hash: taskcluster/docker/ci/Dockerfile:24-45
Warn: npmCommand not pinned by hash: workers/docker-worker/test/images/test/Dockerfile:4
Warn: pipCommand not pinned by hash: clients/client-py/release.sh:26
Warn: pipCommand not pinned by hash: clients/client-py/release.sh:27
Warn: goCommand not pinned by hash: tools/taskcluster-proxy/build.sh:81
Warn: goCommand not pinned by hash: workers/generic-worker/build.sh:134
Warn: goCommand not pinned by hash: workers/generic-worker/build.sh:135
Warn: goCommand not pinned by hash: workers/generic-worker/build.sh:136
Info: 0 out of 12 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 5 third-party GitHubAction dependencies pinned
Info: 0 out of 12 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 2 pipCommand dependencies pinned
Info: 3 out of 7 goCommand dependencies pinned