Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_binaries.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/build_binaries.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_binaries.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/build_binaries.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_binaries.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/build_binaries.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/debian_packages.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/debian_packages.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linters.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/linters.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linters.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/linters.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linters.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/linters.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/linters.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/linters.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linters.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/linters.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linters.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/linters.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rpm_packages.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/rpm_packages.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rpm_packages.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/rpm_packages.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rpm_packages.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/rpm_packages.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rpm_packages.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/rpm_packages.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/miniflux/v2/tests.yml/main?enable=pin
Warn: containerImage not pinned by hash: packaging/debian/Dockerfile:1
Warn: containerImage not pinned by hash: packaging/docker/alpine/Dockerfile:1
Warn: containerImage not pinned by hash: packaging/docker/alpine/Dockerfile:7: pin your Docker image by updating docker.io/library/alpine:3.21 to docker.io/library/alpine:3.21@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: packaging/docker/distroless/Dockerfile:1
Warn: containerImage not pinned by hash: packaging/docker/distroless/Dockerfile:6: pin your Docker image by updating gcr.io/distroless/base-debian12:nonroot to gcr.io/distroless/base-debian12:nonroot@sha256:23fa4a8575bc94e586b94fb9b1dbce8a6d219ed97f805369079eebab54c2cb23
Warn: containerImage not pinned by hash: packaging/rpm/Dockerfile:1
Warn: containerImage not pinned by hash: packaging/rpm/Dockerfile:7: pin your Docker image by updating rockylinux:9 to rockylinux:9@sha256:d7be1c094cc5845ee815d4632fe377514ee6ebcf8efaed6892889657e5ddaaa6
Warn: npmCommand not pinned by hash: .github/workflows/linters.yml:54
Warn: npmCommand not pinned by hash: .github/workflows/linters.yml:18
Info: 0 out of 26 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 16 third-party GitHubAction dependencies pinned
Info: 0 out of 7 containerImage dependencies pinned
Info: 0 out of 2 npmCommand dependencies pinned