Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-generated.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/check-generated.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-generated.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/check-generated.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-generated.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/check-generated.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-generated.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/check-generated.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/coverage.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/coverage.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/coverage.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverage.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/coverage.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/coverage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-manual.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e-manual.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-manual.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e-manual.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-nightly-34x.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e-nightly-34x.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-nightly-34x.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e-nightly-34x.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-nightly-master.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e-nightly-master.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-nightly-master.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e-nightly-master.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/e2e.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/fuzz-nightly.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/fuzz-nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/fuzz-nightly.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/fuzz-nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/fuzz-nightly.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/fuzz-nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/fuzz-nightly.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/fuzz-nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linter.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/linter.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/linter.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/linter.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pre-release.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/pre-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pre-release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/pre-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pre-release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/pre-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pre-release.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/pre-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pre-release.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/pre-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/proto-lint.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/proto-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/proto-lint.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/proto-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/proto-lint.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/proto-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/stale.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:138: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/tendermint/tendermint/tests.yml/main?enable=pin
Warn: containerImage not pinned by hash: DOCKER/Dockerfile:2
Warn: containerImage not pinned by hash: DOCKER/Dockerfile:11: pin your Docker image by updating golang:1.18-alpine to golang:1.18-alpine@sha256:77f25981bd57e60a510165f3be89c901aec90453fd0f1c5a45691f6cb1528807
Warn: containerImage not pinned by hash: DOCKER/Dockerfile.build_c-amazonlinux:1: pin your Docker image by updating amazonlinux:2 to amazonlinux:2@sha256:2c8cd67d220dae7cf95b6a79a128d8eb0563ee08a448bade6e6d256674b483c9
Warn: containerImage not pinned by hash: DOCKER/Dockerfile.testing:1: pin your Docker image by updating golang:latest to golang:latest@sha256:db5d0afbfb4ab648af2393b92e87eaae9ad5e01132803d80caef91b5752d289c
Warn: containerImage not pinned by hash: networks/local/localnode/Dockerfile:1: pin your Docker image by updating alpine:3.7 to alpine:3.7@sha256:8421d9a84432575381bfabd248f1eb56f3aa21d9d7cd2511583c68c9b7511d10
Warn: containerImage not pinned by hash: spec/ivy-proofs/Dockerfile:2: pin your Docker image by updating debian:buster to debian:buster@sha256:58ce6f1271ae1c8a2006ff7d3e54e9874d839f573d8009c20154ad0f2fb0a225
Warn: containerImage not pinned by hash: test/docker/Dockerfile:1: pin your Docker image by updating golang:1.18 to golang:1.18@sha256:50c889275d26f816b5314fc99f55425fa76b18fcaf16af255f5d57f09e1f48da
Warn: containerImage not pinned by hash: test/e2e/docker/Dockerfile:4: pin your Docker image by updating golang:1.18 to golang:1.18@sha256:50c889275d26f816b5314fc99f55425fa76b18fcaf16af255f5d57f09e1f48da
Warn: containerImage not pinned by hash: tools/proto/Dockerfile:1
Warn: containerImage not pinned by hash: tools/proto/Dockerfile:3
Warn: containerImage not pinned by hash: tools/proto/Dockerfile:18: pin your Docker image by updating alpine:edge to alpine:edge@sha256:115729ec5cb049ba6359c3ab005ac742012d92bbaa5b8bc1a878f1e8f62c0cb8
Warn: containerImage not pinned by hash: tools/tm-signer-harness/Dockerfile:2
Warn: pipCommand not pinned by hash: spec/ivy-proofs/Dockerfile:31
Warn: pipCommand not pinned by hash: networks/remote/integration.sh:60
Warn: npmCommand not pinned by hash: scripts/get_nodejs.sh:13
Warn: goCommand not pinned by hash: .github/workflows/check-generated.yml:63
Warn: goCommand not pinned by hash: .github/workflows/check-generated.yml:64
Warn: goCommand not pinned by hash: .github/workflows/fuzz-nightly.yml:21
Info: 0 out of 58 GitHub-owned GitHubAction dependencies pinned
Info: 5 out of 30 third-party GitHubAction dependencies pinned
Info: 0 out of 12 containerImage dependencies pinned
Info: 0 out of 2 pipCommand dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 3 goCommand dependencies pinned