Warn: third-party GitHubAction not pinned by hash: .github/workflows/addToAPMProject.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/addToAPMProject.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/addToAPMProject.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/addToAPMProject.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/github-commands-comment.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/github-commands-comment.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labeler.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/labeler.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/microbenchmark.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/microbenchmark.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/updatecli.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/updatecli.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/updatecli.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/updatecli.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/updatecli.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/updatecli.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/updatecli.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/apm-agent-go/updatecli.yml/main?enable=pin
Warn: containerImage not pinned by hash: internal/tracecontexttest/Dockerfile:1: pin your Docker image by updating golang:latest to golang:latest@sha256:1bcf8844d2464a6485c87646f9da684610758eb1a2df63c8a6e7ca47c64f8655
Warn: containerImage not pinned by hash: internal/tracecontexttest/Dockerfile-harness:1: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: internal/tracecontexttest/Dockerfile-harness:6: pin your Docker image by updating python:3.12.5-slim-bookworm to python:3.12.5-slim-bookworm@sha256:c24c34b502635f1f7c4e99dc09a2cbd85d480b7dcfd077198c6b5af138906390
Warn: containerImage not pinned by hash: scripts/Dockerfile-sqlserver:1: pin your Docker image by updating mcr.microsoft.com/mssql/server:2022-latest to mcr.microsoft.com/mssql/server:2022-latest@sha256:147ee765ff1db3b86ce6ec05908e51fd0dab2feda5dd85b2721f28c77ca305eb
Warn: containerImage not pinned by hash: scripts/Dockerfile-testing:2: pin your Docker image by updating golang:latest to golang:latest@sha256:1bcf8844d2464a6485c87646f9da684610758eb1a2df63c8a6e7ca47c64f8655
Warn: pipCommand not pinned by hash: internal/tracecontexttest/Dockerfile-harness:7
Warn: goCommand not pinned by hash: scripts/ci/setenv.sh:48
Warn: goCommand not pinned by hash: scripts/ci/setenv.sh:49
Warn: goCommand not pinned by hash: scripts/ci/setenv.sh:50
Info: 0 out of 16 GitHub-owned GitHubAction dependencies pinned
Info: 4 out of 13 third-party GitHubAction dependencies pinned
Info: 0 out of 5 containerImage dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 3 goCommand dependencies pinned