Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:303: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:306: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:311: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:319: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:207: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:244: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:247: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:252: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labeler.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/labeler.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pypi.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pypi.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pypi.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/pypi.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/translations.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/translations.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/translations.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/translations.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/translations.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/translations.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/translations.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/indico/indico/translations.yml/master?enable=pin
Warn: downloadThenRun not pinned by hash: .github/workflows/build.yml:53
Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:317
Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:56
Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:116
Warn: downloadThenRun not pinned by hash: .github/workflows/ci.yml:258
Warn: pipCommand not pinned by hash: .github/workflows/codeql-analysis.yml:45
Warn: pipCommand not pinned by hash: .github/workflows/codeql-analysis.yml:46
Warn: pipCommand not pinned by hash: .github/workflows/codeql-analysis.yml:47
Warn: pipCommand not pinned by hash: .github/workflows/pypi.yml:35
Warn: pipCommand not pinned by hash: .github/workflows/pypi.yml:46
Warn: pipCommand not pinned by hash: .github/workflows/translations.yml:36
Warn: pipCommand not pinned by hash: .github/workflows/translations.yml:37
Warn: downloadThenRun not pinned by hash: .github/workflows/translations.yml:42
Info: 0 out of 40 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 3 third-party GitHubAction dependencies pinned
Info: 0 out of 6 downloadThenRun dependencies pinned
Info: 4 out of 4 npmCommand dependencies pinned
Info: 0 out of 7 pipCommand dependencies pinned