Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/benchmark.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmark.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/benchmark.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/benchmark.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/benchmark.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/benchmark.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/discord.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/discord.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gh-release.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/gh-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gh-release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/gh-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-docker.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-docker.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/node-docker.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/node-docker.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/node-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prerelease.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prerelease.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prerelease.yml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/prerelease.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/query-docker.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/query-docker.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/query-docker.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/query-docker.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/query-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/subquery/subql/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: .github/workflows/scripts/benchmark/Dockerfile:1: pin your Docker image by updating node:lts to node:lts@sha256:0b5b940c21ab03353de9042f9166c75bcfc53c4cd0508c7fd88576646adbf875
Warn: containerImage not pinned by hash: .gitpod.dockerfile:1: pin your Docker image by updating gitpod/workspace-postgresql to gitpod/workspace-postgresql@sha256:166b76937e29ba41e8e40a8f5bb49b7089da47614a004b60398daacee75f1f2a
Warn: containerImage not pinned by hash: packages/node/Dockerfile:2
Warn: containerImage not pinned by hash: packages/node/Dockerfile:19: pin your Docker image by updating node:lts-alpine to node:lts-alpine@sha256:41e4389f3d988d2ed55392df4db1420ad048ae53324a8e2b7c6d19508288107e
Warn: containerImage not pinned by hash: packages/node/docker/pg-Dockerfile:1: pin your Docker image by updating postgres:16-alpine to postgres:16-alpine@sha256:7c8c4bf319769e3daf2545ba435248edc650d3621de678db6d9846581036e3da
Warn: containerImage not pinned by hash: packages/query/Dockerfile:2
Warn: containerImage not pinned by hash: packages/query/Dockerfile:20: pin your Docker image by updating node:lts-alpine to node:lts-alpine@sha256:41e4389f3d988d2ed55392df4db1420ad048ae53324a8e2b7c6d19508288107e
Warn: containerImage not pinned by hash: test/Dockerfile:1: pin your Docker image by updating node:lts-bullseye to node:lts-bullseye@sha256:f16d8e8af67bb6361231e932b8b3e7afa040cbfed181719a450b02c3821b26c1
Warn: containerImage not pinned by hash: test/pg-Dockerfile:1: pin your Docker image by updating postgres:16-alpine to postgres:16-alpine@sha256:7c8c4bf319769e3daf2545ba435248edc650d3621de678db6d9846581036e3da
Warn: npmCommand not pinned by hash: .github/workflows/scripts/benchmark/Dockerfile:18
Warn: npmCommand not pinned by hash: scripts/build.sh:5
Info: 0 out of 20 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 45 third-party GitHubAction dependencies pinned
Info: 0 out of 9 containerImage dependencies pinned
Info: 0 out of 2 npmCommand dependencies pinned