Warn: third-party GitHubAction not pinned by hash: .github/workflows/example-comment.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/example-comment.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/example-pp.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/example-pp.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:165: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/integration.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/integration.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ruby-version.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/ruby-version.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tagpr.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/tagpr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tagpr.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/tagpr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tagpr.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/tagpr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/k1LoW/github-script-ruby/test.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating ghcr.io/k1low/github-script-ruby-base:v2.3.0 to ghcr.io/k1low/github-script-ruby-base:v2.3.0@sha256:7e52f51856b83e336631fc4029b8bf45d08a8f90c3797ec548010c3c77fd7394
Warn: containerImage not pinned by hash: docker/Dockerfile:1: pin your Docker image by updating rubylang/ruby:3.1-dev-focal to rubylang/ruby:3.1-dev-focal@sha256:98239911233fe98e70b3ffb39a1e7e7c147515e40507d57bf54e59acda70eedc
Info: 0 out of 15 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 12 third-party GitHubAction dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned