Warn: third-party GitHubAction not pinned by hash: .github/workflows/addToProject.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/addToProject.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/catalog-info.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/catalog-info.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/catalog-info.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/catalog-info.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-build.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/docs-build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-cleanup.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/docs-cleanup.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labeler.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/labeler.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labeler.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/labeler.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labeler.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/labeler.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labeler.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/labeler.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labeler.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/labeler.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labeler.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/labeler.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pre-post-release.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/pre-post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pre-post-release.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/pre-post-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pre-post-release.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/pre-post-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-step-3.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/release-step-3.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-step-3.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/release-step-3.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-step-3.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/release-step-3.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-step-3.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/release-step-3.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-step-3.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/release-step-3.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-step-3.yml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/release-step-3.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-step-3.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/release-step-3.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/snapshot.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/snapshot.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/snapshot.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/snapshot.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/snapshot.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/snapshot.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/snapshot.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-reporter.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/test-reporter.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/updatecli.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/updatecli.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/updatecli.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/updatecli.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/updatecli.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/updatecli.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/updatecli.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/elastic/ecs-logging-java/updatecli.yml/main?enable=pin
Info: 2 out of 12 GitHub-owned GitHubAction dependencies pinned
Info: 5 out of 29 third-party GitHubAction dependencies pinned