Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto-comment.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/auto-comment.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-latest.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-latest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-latest.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-latest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-latest.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-latest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-latest.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-latest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-latest.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-latest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-release.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-release.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-test.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-test.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-test.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-test.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/docker-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mobsf-test.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/mobsf-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mobsf-test.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/mobsf-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mobsf-test.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/mobsf-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/python-publish.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/python-publish.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/python-publish.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/MobSF/Mobile-Security-Framework-MobSF/python-publish.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:2: pin your Docker image by updating python:3.12-slim-bookworm to python:3.12-slim-bookworm@sha256:bae1a061b657f403aaacb1069a7f67d91f7ef5725ab17ca36abc5f1b2797ff92
Warn: downloadThenRun not pinned by hash: Dockerfile:29-54
Warn: pipCommand not pinned by hash: setup.sh:42
Warn: pipCommand not pinned by hash: .github/workflows/mobsf-test.yml:31
Warn: pipCommand not pinned by hash: .github/workflows/mobsf-test.yml:32
Warn: chocoCommand not pinned by hash: .github/workflows/mobsf-test.yml:57
Warn: pipCommand not pinned by hash: .github/workflows/python-publish.yml:20
Warn: pipCommand not pinned by hash: .github/workflows/python-publish.yml:21
Info: 0 out of 11 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 13 third-party GitHubAction dependencies pinned
Info: 1 out of 6 pipCommand dependencies pinned
Info: 0 out of 1 chocoCommand dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned