Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/benchmark.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmark.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/benchmark.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/benchmark.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmark.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/benchmark.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/discord.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/discord.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gh-release.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/gh-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gh-release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/gh-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-docker.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-docker.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-docker.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prerelease.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prerelease.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/query-docker.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/query-docker.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/query-docker.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: .github/workflows/scripts/benchmark/Dockerfile:1: pin your Docker image by updating node:lts to node:lts@sha256:2fa6c977460b56d4d8278947ab56faeb312bc4cc6c4cf78920c6de27812f51c5
Warn: containerImage not pinned by hash: .gitpod.dockerfile:1: pin your Docker image by updating gitpod/workspace-postgresql to gitpod/workspace-postgresql@sha256:166b76937e29ba41e8e40a8f5bb49b7089da47614a004b60398daacee75f1f2a
Warn: containerImage not pinned by hash: packages/node/Dockerfile:2
Warn: containerImage not pinned by hash: packages/node/Dockerfile:19: pin your Docker image by updating node:lts-alpine to node:lts-alpine@sha256:10962e8568729b0cfd506170c5a2d1918a2c10ac08c0e6900180b4bac061adc9
Warn: containerImage not pinned by hash: packages/node/docker/pg-Dockerfile:1: pin your Docker image by updating postgres:16-alpine to postgres:16-alpine@sha256:ef2235fd13b6cb29728a98ee17862ff5c9b7d20515a9b34804da4a45062695f6
Warn: containerImage not pinned by hash: packages/query/Dockerfile:2
Warn: containerImage not pinned by hash: packages/query/Dockerfile:20: pin your Docker image by updating node:lts-alpine to node:lts-alpine@sha256:10962e8568729b0cfd506170c5a2d1918a2c10ac08c0e6900180b4bac061adc9
Warn: containerImage not pinned by hash: test/Dockerfile:1: pin your Docker image by updating node:lts-bullseye to node:lts-bullseye@sha256:125996cb2451482467fc2aa4d7653075894b08e9b7711bcd761044ca270a083e
Warn: containerImage not pinned by hash: test/pg-Dockerfile:1: pin your Docker image by updating postgres:16-alpine to postgres:16-alpine@sha256:ef2235fd13b6cb29728a98ee17862ff5c9b7d20515a9b34804da4a45062695f6
Warn: npmCommand not pinned by hash: .github/workflows/scripts/benchmark/Dockerfile:18
Warn: npmCommand not pinned by hash: scripts/build.sh:5
Info: 0 out of 20 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 45 third-party GitHubAction dependencies pinned
Info: 0 out of 9 containerImage dependencies pinned
Info: 0 out of 2 npmCommand dependencies pinned