Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:143: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:150: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:164: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:170: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:185: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:187: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:208: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:210: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:161: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/go.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lock.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/lock.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/shell.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/shell.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/shell.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/gogs/gogs/shell.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:14: pin your Docker image by updating alpine:3.21 to alpine:3.21@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Info: 0 out of 20 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 26 third-party GitHubAction dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned