Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/downstream.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/downstream.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/downstream.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/downstream.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/downstream.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/downstream.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/downstream.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/downstream.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/enforce-label.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/enforce-label.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prep-release.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/prep-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prep-release.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/prep-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-changelog.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/publish-changelog.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-changelog.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/publish-changelog.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-changelog.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/publish-changelog.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/publish-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/publish-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-release.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/publish-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-release.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/publish-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:149: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:162: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:189: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:138: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:172: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:123: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/jupyter/jupyter_core/test.yml/main?enable=pin
Warn: pipCommand not pinned by hash: .github/workflows/test.yml:160
Warn: pipCommand not pinned by hash: .github/workflows/test.yml:50
Warn: pipCommand not pinned by hash: .github/workflows/test.yml:62
Info: 0 out of 22 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 35 third-party GitHubAction dependencies pinned
Info: 0 out of 3 pipCommand dependencies pinned