Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/continuous-integration-workflow.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/continuous-integration-workflow.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/continuous-integration-workflow.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/continuous-integration-workflow.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/continuous-integration-workflow.yml:123: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/continuous-integration-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/continuous-integration-workflow.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/continuous-integration-workflow.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/continuous-integration-workflow.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/continuous-integration-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dependabot-auto-merge-forward.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/dependabot-auto-merge-forward.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-auto-merge-forward.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/dependabot-auto-merge-forward.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-auto-merge-forward.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/dependabot-auto-merge-forward.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy-docs.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/deploy-docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gradle-wrapper-upgrade-execution.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/gradle-wrapper-upgrade-execution.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gradle-wrapper-upgrade-execution.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/gradle-wrapper-upgrade-execution.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gradle-wrapper-upgrade-execution.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/gradle-wrapper-upgrade-execution.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mark-duplicate-dependabot-prs.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/mark-duplicate-dependabot-prs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/merge-dependabot-pr.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/merge-dependabot-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/merge-dependabot-pr.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/merge-dependabot-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/merge-dependabot-pr.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/merge-dependabot-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/milestone-spring-releasetrain.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/milestone-spring-releasetrain.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-build-workflow.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/pr-build-workflow.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-build-workflow.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/pr-build-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-build-workflow.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/pr-build-workflow.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-build-workflow.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/pr-build-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-build-workflow.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/pr-build-workflow.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-build-workflow.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/pr-build-workflow.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-scheduler.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/release-scheduler.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-dependabot-auto-merge-forward.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/trigger-dependabot-auto-merge-forward.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-dependabot.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/update-dependabot.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-dependabot.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/update-dependabot.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-dependabot.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/update-dependabot.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-scheduled-release-version.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/spring-projects/spring-security/update-scheduled-release-version.yml/main?enable=pin
Info: 0 out of 15 GitHub-owned GitHubAction dependencies pinned
Info: 2 out of 16 third-party GitHubAction dependencies pinned