Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot-approve-and-automerge.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/dotnet/samples/dependabot-approve-and-automerge.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dotnet-code-metrics.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/dotnet/samples/dotnet-code-metrics.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dotnet-code-metrics.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/dotnet/samples/dotnet-code-metrics.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dotnet-code-metrics.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/dotnet/samples/dotnet-code-metrics.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/version-sweep.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/dotnet/samples/version-sweep.yml/main?enable=pin
Warn: containerImage not pinned by hash: core/nativeaot/HelloWorld/Dockerfile:1
Warn: containerImage not pinned by hash: core/nativeaot/HelloWorld/Dockerfile:13: pin your Docker image by updating mcr.microsoft.com/dotnet/runtime-deps:8.0 to mcr.microsoft.com/dotnet/runtime-deps:8.0@sha256:933c58aa27a581d6186531ef660a12a7b91c274ee33d6702e40a77a07bd30ade
Warn: containerImage not pinned by hash: core/nativeaot/HelloWorld/Dockerfile.windowsservercore-x64:1
Warn: containerImage not pinned by hash: core/nativeaot/HelloWorld/Dockerfile.windowsservercore-x64:13: pin your Docker image by updating mcr.microsoft.com/windows/nanoserver:ltsc2022-amd64 to mcr.microsoft.com/windows/nanoserver:ltsc2022-amd64@sha256:986d64d5434a3bba744f09faaaf912e56f8a1bde3c1b947148f7b331df42ec92
Warn: containerImage not pinned by hash: core/workers/background-service/Dockerfile:4
Warn: containerImage not pinned by hash: core/workers/background-service/Dockerfile:7
Warn: containerImage not pinned by hash: core/workers/background-service/Dockerfile:15
Warn: containerImage not pinned by hash: core/workers/background-service/Dockerfile:18
Warn: containerImage not pinned by hash: core/workers/cloud-service/Dockerfile:1
Warn: containerImage not pinned by hash: core/workers/cloud-service/Dockerfile:9
Warn: containerImage not pinned by hash: core/workers/cloud-service/Dockerfile:17
Warn: containerImage not pinned by hash: core/workers/cloud-service/Dockerfile:20
Warn: containerImage not pinned by hash: framework/docker/ConsoleRandomAnswerGenerator/ConsoleRandomAnswerGenerator/Dockerfile:1
Warn: containerImage not pinned by hash: github-actions/DotNet.GitHubAction/Dockerfile:2
Warn: containerImage not pinned by hash: github-actions/DotNet.GitHubAction/Dockerfile:20: pin your Docker image by updating mcr.microsoft.com/dotnet/sdk:6.0 to mcr.microsoft.com/dotnet/sdk:6.0@sha256:c8fdd06e430de9f4ddd066b475ea350d771f341b77dd5ff4c2fafa748e3f2ef2
Warn: containerImage not pinned by hash: orleans/ShoppingCart/Silo/Dockerfile:3
Warn: containerImage not pinned by hash: orleans/ShoppingCart/Silo/Dockerfile:9
Warn: containerImage not pinned by hash: orleans/ShoppingCart/Silo/Dockerfile:21
Warn: containerImage not pinned by hash: orleans/ShoppingCart/Silo/Dockerfile:24
Warn: containerImage not pinned by hash: orleans/Voting/Dockerfile:3
Warn: containerImage not pinned by hash: orleans/Voting/Dockerfile:10
Warn: containerImage not pinned by hash: orleans/Voting/Dockerfile:18
Warn: containerImage not pinned by hash: orleans/Voting/Dockerfile:21
Warn: nugetCommand not pinned by hash: core/workers/background-service/Dockerfile:10: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: core/workers/cloud-service/Dockerfile:12: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: orleans/ShoppingCart/Silo/Dockerfile:16: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: orleans/Voting/Dockerfile:13: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: npmCommand not pinned by hash: .github/workflows/markdownlint.yml:24
Info: 5 out of 6 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 4 third-party GitHubAction dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 23 containerImage dependencies pinned
Info: 0 out of 4 nugetCommand dependencies pinned