Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/detector-tests.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/detector-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/detector-tests.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/detector-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/detector-tests.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/detector-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/detector-tests.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/detector-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/performance.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/performance.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/performance.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/performance.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/performance.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/performance.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/secrets.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/secrets.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/smoke.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/smoke.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/smoke.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/smoke.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/smoke.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/trufflesecurity/trufflehog/test.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:11: pin your Docker image by updating alpine:3.21 to alpine:3.21@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: Dockerfile.goreleaser:1: pin your Docker image by updating alpine:3.21 to alpine:3.21@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: hack/Dockerfile.protos:3: pin your Docker image by updating golang:1.24-bullseye to golang:1.24-bullseye@sha256:aa106963247f64275bd459b6b713978f1633160da53f58115922964ab0b9eae7
Warn: pipCommand not pinned by hash: hack/Dockerfile.protos:21
Warn: goCommand not pinned by hash: hack/Dockerfile.protos:29
Warn: goCommand not pinned by hash: .github/workflows/test.yml:33
Info: 0 out of 23 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 11 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 1 out of 3 goCommand dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned