Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/danielgerlag/workflow-core/dotnet.yml/master?enable=pin
Warn: containerImage not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile:1
Warn: containerImage not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile:5
Warn: containerImage not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile:13
Warn: containerImage not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile:16
Warn: containerImage not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile.original:1
Warn: containerImage not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile.original:5
Warn: containerImage not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile.original:13
Warn: containerImage not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile.original:16
Warn: nugetCommand not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile:8: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: src/samples/WebApiSample/WebApiSample/Dockerfile.original:8: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/dotnet.yml:91: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/dotnet.yml:108: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/dotnet.yml:125: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/dotnet.yml:142: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/dotnet.yml:23: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/dotnet.yml:40: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/dotnet.yml:57: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/dotnet.yml:74: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Info: 0 out of 16 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 8 containerImage dependencies pinned
Info: 0 out of 10 nugetCommand dependencies pinned