Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/coverage-comment.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/coverage-comment.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-external-phase-1.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/e2e-external-phase-1.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-external-phase-2.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/e2e-external-phase-2.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-external-phase-2.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/e2e-external-phase-2.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-external-phase-2.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/e2e-external-phase-2.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/manual-release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/manual-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/py-cov-action/python-coverage-comment-action/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:2: pin your Docker image by updating ghcr.io/py-cov-action/python-coverage-comment-action-base:v7 to ghcr.io/py-cov-action/python-coverage-comment-action-base:v7@sha256:3b3dfea05feb58710fa7e3298aeb3ee6dcf15c0ca8976d17e177c63d5e1cebe3
Warn: containerImage not pinned by hash: Dockerfile.build:5: pin your Docker image by updating python:3.14-slim to python:3.14-slim@sha256:4ed33101ee7ec299041cc41dd268dae17031184be94384b1ce7936dc4e5dead3
Warn: pipCommand not pinned by hash: Dockerfile:5
Warn: pipCommand not pinned by hash: Dockerfile.build:25
Info:   0 out of   9 GitHub-owned GitHubAction dependencies pinned
Info:   0 out of  12 third-party GitHubAction dependencies pinned
Info:   0 out of   2 pipCommand dependencies pinned
Info:   0 out of   2 containerImage dependencies pinned