Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/backports.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/backports.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/backports.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/backports.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/backports.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/backports.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cypress.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/cypress.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cypress.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/cypress.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cypress.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/cypress.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cypress.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/cypress.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cypress.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/cypress.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cypress.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/cypress.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/docs.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flake8.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/flake8.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/flake8.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/flake8.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github-release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/github-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-pypi.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-pypi.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-pypi.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-pypi.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-pypi.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-pypi.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-test-pypi.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-test-pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-test-pypi.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-test-pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-test-pypi.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-test-pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-test-pypi.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-test-pypi.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-test-pypi.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/publish-test-pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pyright.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pyright.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pyright.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pyright.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pyright.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pyright.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:160: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:176: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pytest.yml:210: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pytest.yml:218: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:229: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:242: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:251: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pytest.yml:259: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pytest.yml:265: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:272: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:287: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:304: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:314: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:330: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:333: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:345: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:352: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pytest.yml:389: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/pytest.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/towncrier.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/towncrier.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/towncrier.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/ckan/ckan/towncrier.yml/master?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:3
Warn: downloadThenRun not pinned by hash: bin/remove-old-git-branches.sh:21
Warn: pipCommand not pinned by hash: test-infrastructure/install_deps.sh:11
Warn: pipCommand not pinned by hash: test-infrastructure/install_deps.sh:12
Warn: pipCommand not pinned by hash: test-infrastructure/install_deps.sh:13
Warn: pipCommand not pinned by hash: test-infrastructure/install_deps.sh:14
Warn: pipCommand not pinned by hash: test-infrastructure/install_deps.sh:15
Warn: pipCommand not pinned by hash: .github/workflows/cypress.yml:58
Warn: pipCommand not pinned by hash: .github/workflows/cypress.yml:59
Warn: pipCommand not pinned by hash: .github/workflows/docs.yml:27
Warn: pipCommand not pinned by hash: .github/workflows/docs.yml:28
Warn: pipCommand not pinned by hash: .github/workflows/flake8.yml:20
Warn: pipCommand not pinned by hash: .github/workflows/publish-pypi.yml:22
Warn: pipCommand not pinned by hash: .github/workflows/publish-test-pypi.yml:26
Warn: pipCommand not pinned by hash: .github/workflows/pyright.yml:28
Warn: pipCommand not pinned by hash: .github/workflows/pytest.yml:342
Warn: pipCommand not pinned by hash: .github/workflows/towncrier.yml:20
Info: 0 out of 46 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 8 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 0 out of 15 pipCommand dependencies pinned
Info: 1 out of 1 npmCommand dependencies pinned