Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmarks-last-release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/benchmarks-last-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmarks-last-release.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/benchmarks-last-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmarks-last-release.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/benchmarks-last-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmarks-last-release.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/benchmarks-last-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmarks.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/benchmarks.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmarks.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/benchmarks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmarks.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/benchmarks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:146: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:154: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:202: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:210: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:258: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:266: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:289: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:310: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:315: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci-additional.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci-additional.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:191: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hypothesis.yaml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/hypothesis.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hypothesis.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/hypothesis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hypothesis.yaml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/hypothesis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hypothesis.yaml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/hypothesis.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hypothesis.yaml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/hypothesis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hypothesis.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/hypothesis.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hypothesis.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/hypothesis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/label-prs.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/label-prs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-wheels.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/nightly-wheels.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-wheels.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/nightly-wheels.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-test-results.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/publish-test-results.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi-release.yaml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/pypi-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/upstream-dev-ci.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/upstream-dev-ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/upstream-dev-ci.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/upstream-dev-ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/upstream-dev-ci.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/upstream-dev-ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/upstream-dev-ci.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/upstream-dev-ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/upstream-dev-ci.yaml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/upstream-dev-ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/upstream-dev-ci.yaml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/upstream-dev-ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/upstream-dev-ci.yaml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/upstream-dev-ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/upstream-dev-ci.yaml:143: update your workflow using https://app.stepsecurity.io/secureworkflow/pydata/xarray/upstream-dev-ci.yaml/main?enable=pin
Warn: pipCommand not pinned by hash: ci/install-upstream-wheels.sh:30
Warn: pipCommand not pinned by hash: ci/install-upstream-wheels.sh:41
Warn: pipCommand not pinned by hash: ci/install-upstream-wheels.sh:49
Warn: pipCommand not pinned by hash: ci/install-upstream-wheels.sh:50
Warn: pipCommand not pinned by hash: .github/workflows/nightly-wheels.yml:20
Warn: pipCommand not pinned by hash: .github/workflows/nightly-wheels.yml:21
Warn: pipCommand not pinned by hash: .github/workflows/pypi-release.yaml:25
Warn: pipCommand not pinned by hash: .github/workflows/pypi-release.yaml:26
Warn: pipCommand not pinned by hash: .github/workflows/pypi-release.yaml:69
Info: 0 out of 33 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 29 third-party GitHubAction dependencies pinned
Info: 1 out of 10 pipCommand dependencies pinned