Warn: third-party GitHubAction not pinned by hash: .github/workflows/cifuzz.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/cifuzz.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cifuzz.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/cifuzz.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cifuzz.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/cifuzz.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/golangci-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/homepage.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/homepage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/homepage.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/homepage.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/homepage.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/homepage.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-images.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/test-images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-images.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/test-images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-images.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/test-images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-images.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/test-images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-images.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/test-images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tinygo.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/tinygo.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tinygo.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/u-root/u-root/tinygo.yml/main?enable=pin
Warn: containerImage not pinned by hash: .circleci/images/kernel-amd64/Dockerfile:5
Warn: containerImage not pinned by hash: .circleci/images/kernel-arm/Dockerfile:5
Warn: containerImage not pinned by hash: .circleci/images/kernel-arm64/Dockerfile:5
Warn: containerImage not pinned by hash: .circleci/images/multiboot-test-kernel-amd64/Dockerfile:5
Warn: containerImage not pinned by hash: .circleci/images/ovmf-amd64/Dockerfile:5
Warn: containerImage not pinned by hash: .circleci/images/ovmf-arm64/Dockerfile:5
Warn: containerImage not pinned by hash: .circleci/images/test-image-tamago/Dockerfile:1: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:67cadaff1dca187079fce41360d5a7eb6f7dcd3745e53c79ad5efd8563118240
Warn: containerImage not pinned by hash: .circleci/images/uefipayload-amd64/Dockerfile:5
Warn: containerImage not pinned by hash: .circleci/images/upl-fit-amd64/Dockerfile:5
Warn: containerImage not pinned by hash: .circleci/images/upl-fit-arm64/Dockerfile:5
Warn: containerImage not pinned by hash: tools/golang_patched_dce/Dockerfile:1: pin your Docker image by updating golang:1.13.5-alpine to golang:1.13.5-alpine@sha256:0991060a1447cf648bab7f6bb60335d1243930e38420bee8fec3db1267b84cfa
Warn: pipCommand not pinned by hash: .circleci/images/uefipayload-amd64/Dockerfile:29
Warn: pipCommand not pinned by hash: .circleci/images/upl-fit-amd64/Dockerfile:29
Warn: pipCommand not pinned by hash: .circleci/images/upl-fit-arm64/Dockerfile:30
Warn: npmCommand not pinned by hash: .github/workflows/homepage.yml:17
Warn: goCommand not pinned by hash: .github/workflows/tests.yml:57
Info: 0 out of 22 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 9 third-party GitHubAction dependencies pinned
Info: 0 out of 11 containerImage dependencies pinned
Info: 0 out of 3 pipCommand dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned