Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-c.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/integration-c.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-csharp.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/integration-csharp.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-go.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/integration-go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-node.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/integration-node.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-php.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/integration-php.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-python.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/integration-python.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-shell.yml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/readmeio/httpsnippet/integration-shell.yml/main?enable=pin
Warn: containerImage not pinned by hash: integrations/c.Dockerfile:1: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f
Warn: containerImage not pinned by hash: integrations/csharp.Dockerfile:1
Warn: containerImage not pinned by hash: integrations/csharp.Dockerfile:2: pin your Docker image by updating mcr.microsoft.com/dotnet/sdk:7.0-alpine3.18 to mcr.microsoft.com/dotnet/sdk:7.0-alpine3.18@sha256:8879b75311721e147c70b31d2d977d4652d54bff0f652d50829b9c21563f6cd4
Warn: containerImage not pinned by hash: integrations/go.Dockerfile:1: pin your Docker image by updating golang:1.20.5-alpine3.18 to golang:1.20.5-alpine3.18@sha256:fd9d9d7194ec40a9a6ae89fcaef3e47c47de7746dd5848ab5343695dbbd09f8c
Warn: containerImage not pinned by hash: integrations/node.Dockerfile:1: pin your Docker image by updating node:18-alpine to node:18-alpine@sha256:8d6421d663b4c28fd3ebc498332f249011d118945588d0a35cb9bc4b8ca09d9e
Warn: containerImage not pinned by hash: integrations/php.Dockerfile:1
Warn: containerImage not pinned by hash: integrations/php.Dockerfile:7: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f
Warn: containerImage not pinned by hash: integrations/python.Dockerfile:1: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f
Warn: containerImage not pinned by hash: integrations/shell.Dockerfile:1: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f
Warn: npmCommand not pinned by hash: integrations/c.Dockerfile:19
Warn: nugetCommand not pinned by hash: integrations/csharp.Dockerfile:26-29: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: npmCommand not pinned by hash: integrations/csharp.Dockerfile:36
Warn: npmCommand not pinned by hash: integrations/go.Dockerfile:20
Warn: npmCommand not pinned by hash: integrations/node.Dockerfile:16-17
Warn: npmCommand not pinned by hash: integrations/node.Dockerfile:16-17
Warn: npmCommand not pinned by hash: integrations/php.Dockerfile:26
Warn: pipCommand not pinned by hash: integrations/python.Dockerfile:11-13
Warn: npmCommand not pinned by hash: integrations/python.Dockerfile:20
Warn: npmCommand not pinned by hash: integrations/shell.Dockerfile:19
Info: 0 out of 13 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 9 containerImage dependencies pinned
Info: 1 out of 9 npmCommand dependencies pinned
Info: 0 out of 1 nugetCommand dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned