Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto-assign-issue.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/auto-assign-issue.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto-assign-pull-request.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/auto-assign-pull-request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check_openfeature_pr.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/check_openfeature_pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check_openfeature_pr.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/check_openfeature_pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-helm.yaml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-helm.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-helm.yaml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-helm.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-helm.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-helm.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-helm.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-helm.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-helm.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-helm.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-helm.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-helm.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-kotlin.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-kotlin.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-kotlin.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-kotlin.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-kotlin.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-kotlin.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-kotlin.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci-kotlin.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:127: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:146: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:176: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/close-stale.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/close-stale.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/doc-deploy.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/doc-deploy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/doc-deploy.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/doc-deploy.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/doc-deploy.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/doc-deploy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/doc-test.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/doc-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/doc-test.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/doc-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/doc-test.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/doc-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint-flag-files.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/lint-flag-files.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-lint.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/pr-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-lint.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/pr-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-lint.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/pr-lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-helm.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-helm.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-helm.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-helm.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-helm.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-helm.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-helm.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-helm.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-helm.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-helm.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-helm.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-helm.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-kotlin-provider.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-kotlin-provider.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-kotlin-provider.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-kotlin-provider.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-kotlin-provider.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-kotlin-provider.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-kotlin-provider.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-kotlin-provider.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-python-provider.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-python-provider.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-python-provider.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-python-provider.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-python-provider.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release-python-provider.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:315: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:321: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:335: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:347: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:143: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:162: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:164: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:174: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:261: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:267: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:278: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:290: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:197: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:202: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:223: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:235: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/repostats-collector.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/repostats-collector.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sponsors.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/sponsors.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sponsors.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/sponsors.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sponsors.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/sponsors.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unassign-issue.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/unassign-issue.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unassign-issue.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/unassign-issue.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unassign-issue.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/unassign-issue.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-sdk-versions.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/update-sdk-versions.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-sdk-versions.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/update-sdk-versions.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-sdk-versions.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/thomaspoignant/go-feature-flag/update-sdk-versions.yml/main?enable=pin
Warn: containerImage not pinned by hash: cmd/cli/Dockerfile:1: pin your Docker image by updating gcr.io/distroless/base-debian12:latest to gcr.io/distroless/base-debian12:latest@sha256:27769871031f67460f1545a52dfacead6d18a9f197db77110cfc649ca2a91f44
Warn: containerImage not pinned by hash: cmd/lint/Dockerfile:1: pin your Docker image by updating gcr.io/distroless/base-debian12:latest to gcr.io/distroless/base-debian12:latest@sha256:27769871031f67460f1545a52dfacead6d18a9f197db77110cfc649ca2a91f44
Warn: containerImage not pinned by hash: cmd/relayproxy/DockerfileGoreleaser:1: pin your Docker image by updating gcr.io/distroless/base-debian12:latest to gcr.io/distroless/base-debian12:latest@sha256:27769871031f67460f1545a52dfacead6d18a9f197db77110cfc649ca2a91f44
Warn: containerImage not pinned by hash: cmd/relayproxy/DockerfileGoreleaserBookworm:1: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:4b50eb66f977b4062683ff434ef18ac191da862dbe966961bc11990cf5791a8d
Warn: containerImage not pinned by hash: cmd/relayproxy/DockerfileGoreleaserRelayProxy:1: pin your Docker image by updating gcr.io/distroless/base-debian12:latest to gcr.io/distroless/base-debian12:latest@sha256:27769871031f67460f1545a52dfacead6d18a9f197db77110cfc649ca2a91f44
Warn: containerImage not pinned by hash: examples/openfeature_kotlin_server/kotlin-app/Dockerfile:2: pin your Docker image by updating openjdk:11-jre-slim to openjdk:11-jre-slim@sha256:93af7df2308c5141a751c4830e6b6c5717db102b3b31f012ea29d842dc4f2b02
Warn: containerImage not pinned by hash: examples/openfeature_nodejs/nodejs-app/Dockerfile:1: pin your Docker image by updating node:18-alpine to node:18-alpine@sha256:8d6421d663b4c28fd3ebc498332f249011d118945588d0a35cb9bc4b8ca09d9e
Warn: containerImage not pinned by hash: examples/openfeature_react/react-app/Dockerfile:1: pin your Docker image by updating node:18-alpine to node:18-alpine@sha256:8d6421d663b4c28fd3ebc498332f249011d118945588d0a35cb9bc4b8ca09d9e
Warn: containerImage not pinned by hash: examples/openfeature_web/webapp/Dockerfile:1: pin your Docker image by updating node:20 to node:20@sha256:6f076db82169a365abca591093bdf020f9e8827a8add8ea3826556c290b340c0
Warn: containerImage not pinned by hash: examples/retriever_configmap/Dockerfile:1: pin your Docker image by updating golang:1.21 to golang:1.21@sha256:4746d26432a9117a5f58e95cb9f954ddf0de128e9d5816886514199316e4a2fb
Warn: npmCommand not pinned by hash: examples/openfeature_nodejs/nodejs-app/Dockerfile:4
Warn: npmCommand not pinned by hash: examples/openfeature_react/react-app/Dockerfile:4
Warn: npmCommand not pinned by hash: examples/openfeature_web/webapp/Dockerfile:4
Warn: npmCommand not pinned by hash: openfeature/provider_tests/integration_tests.sh:40
Warn: npmCommand not pinned by hash: .github/workflows/check_openfeature_pr.yml:18
Warn: npmCommand not pinned by hash: .github/workflows/doc-deploy.yml:18
Warn: npmCommand not pinned by hash: .github/workflows/release.yml:207
Info: 0 out of 66 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 54 third-party GitHubAction dependencies pinned
Info: 0 out of 10 containerImage dependencies pinned
Info: 0 out of 7 npmCommand dependencies pinned