Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/changelog.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/changelog.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/close-stale.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/close-stale.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql_analysis.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/codeql_analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql_analysis.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/codeql_analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql_analysis.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/codeql_analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql_analysis.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/codeql_analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codespell.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/codespell.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/links-fail-fast.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/links-fail-fast.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/links-fail-fast.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/links-fail-fast.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/links-fail-fast.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/links-fail-fast.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/links.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/links.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/links.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/links.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/links.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/links.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/links.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/links.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/protect-released-changelog.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/protect-released-changelog.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/request_codeowners_review.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/open-telemetry/opentelemetry-go-contrib/request_codeowners_review.yml/main?enable=pin
Warn: containerImage not pinned by hash: dependencies.Dockerfile:2
Warn: containerImage not pinned by hash: examples/zipkin/Dockerfile:3: pin your Docker image by updating golang:1.24-alpine to golang:1.24-alpine@sha256:43c094ad24b6ac0546c62193baeb3e6e49ce14d3250845d166c77c25f64b0386
Warn: containerImage not pinned by hash: instrumentation/github.com/aws/aws-lambda-go/otellambda/example/Dockerfile:3
Warn: containerImage not pinned by hash: instrumentation/github.com/aws/aws-lambda-go/otellambda/example/Dockerfile:8
Warn: containerImage not pinned by hash: instrumentation/github.com/aws/aws-sdk-go-v2/otelaws/example/Dockerfile:3
Warn: containerImage not pinned by hash: instrumentation/github.com/aws/aws-sdk-go-v2/otelaws/example/Dockerfile:7
Warn: containerImage not pinned by hash: instrumentation/github.com/emicklei/go-restful/otelrestful/example/Dockerfile:3
Warn: containerImage not pinned by hash: instrumentation/github.com/emicklei/go-restful/otelrestful/example/Dockerfile:7
Warn: containerImage not pinned by hash: instrumentation/github.com/gin-gonic/gin/otelgin/example/Dockerfile:3
Warn: containerImage not pinned by hash: instrumentation/github.com/gin-gonic/gin/otelgin/example/Dockerfile:7
Warn: containerImage not pinned by hash: instrumentation/github.com/gorilla/mux/otelmux/example/Dockerfile:3
Warn: containerImage not pinned by hash: instrumentation/github.com/gorilla/mux/otelmux/example/Dockerfile:7
Warn: containerImage not pinned by hash: instrumentation/github.com/labstack/echo/otelecho/example/Dockerfile:3
Warn: containerImage not pinned by hash: instrumentation/github.com/labstack/echo/otelecho/example/Dockerfile:7
Warn: containerImage not pinned by hash: instrumentation/net/http/httptrace/otelhttptrace/example/Dockerfile:3
Warn: containerImage not pinned by hash: instrumentation/net/http/httptrace/otelhttptrace/example/Dockerfile:7
Warn: containerImage not pinned by hash: instrumentation/net/http/httptrace/otelhttptrace/example/Dockerfile:11
Warn: containerImage not pinned by hash: instrumentation/net/http/otelhttp/example/Dockerfile:3
Warn: containerImage not pinned by hash: instrumentation/net/http/otelhttp/example/Dockerfile:7
Warn: containerImage not pinned by hash: instrumentation/net/http/otelhttp/example/Dockerfile:11
Warn: goCommand not pinned by hash: examples/dice/instrumented/get.sh:6
Info: 1 out of 24 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 5 third-party GitHubAction dependencies pinned
Info: 0 out of 20 containerImage dependencies pinned
Info: 10 out of 11 goCommand dependencies pinned