Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/goreleaser.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/goreleaser.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/goreleaser.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/goreleaser.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/goreleaser.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/goreleaser.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/goreleaser.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish_npm.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/publish_npm.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish_npm.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/publish_npm.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish_wheel.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/publish_wheel.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish_wheel.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/publish_wheel.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish_wheel.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/publish_wheel.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish_wheel.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/publish_wheel.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/shellcheck.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/shellcheck.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/yamllint.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/yoheimuta/protolint/yamllint.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating alpine:3.20.2 to alpine:3.20.2@sha256:0a4eaa0eecf5f8c050e5bba433f58c052be7587ee8af3e8b3910ef9ab5fbe9f5
Warn: goCommand not pinned by hash: .github/install_dep.sh:5
Warn: goCommand not pinned by hash: .github/install_dep.sh:6
Warn: goCommand not pinned by hash: .github/install_dep.sh:7
Warn: goCommand not pinned by hash: .github/install_dep.sh:8
Warn: goCommand not pinned by hash: .github/install_dep.sh:9
Warn: goCommand not pinned by hash: .github/install_dep.sh:10
Warn: goCommand not pinned by hash: .github/install_dep.sh:11
Warn: npmCommand not pinned by hash: .github/workflows/publish_npm.yml:26
Warn: pipCommand not pinned by hash: .github/workflows/publish_wheel.yml:35
Info: 0 out of 16 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 5 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 0 out of 7 goCommand dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned