Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:960: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:963: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:971: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1025: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1038: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1047: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:406: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:770: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:814: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:816: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:713: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:912: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:915: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:921: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:924: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:187: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:193: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:282: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:285: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:291: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:295: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:369: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:476: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:860: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:863: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:872: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:875: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1137: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1140: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1143: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1148: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1151: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1210: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:1222: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:245: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:537: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:546: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:600: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/configure.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/configure.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/configure.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/configure.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/configure.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/configure.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/configure.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/configure.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-link.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/docs-link.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-link.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/docs-link.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/format.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/format.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/format.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/format.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/format.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/format.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/format.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/format.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labeler.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/labeler.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightlies.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/nightlies.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightlies.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/nightlies.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightlies.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/nightlies.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightlies.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/nightlies.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pip.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pip.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pip.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pip.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pip.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pip.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pip.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pip.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pip.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pip.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pip.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pip.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/pip.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-standard.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/reusable-standard.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-standard.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/reusable-standard.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/reusable-standard.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/reusable-standard.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-cibw.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/tests-cibw.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests-cibw.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/tests-cibw.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests-cibw.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/tests-cibw.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests-cibw.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/tests-cibw.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/upstream.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/upstream.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/upstream.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/upstream.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/upstream.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/pybind/pybind11/upstream.yml/master?enable=pin
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:321
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:839
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:544
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:616
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:621
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:725
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:728
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:733
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:776
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:489
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:490
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:1226
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:1227
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:1228
Warn: pipCommand not pinned by hash: .github/workflows/ci.yml:1229
Warn: pipCommand not pinned by hash: .github/workflows/upstream.yml:43
Warn: pipCommand not pinned by hash: .github/workflows/upstream.yml:44
Warn: pipCommand not pinned by hash: .github/workflows/upstream.yml:115
Info: 0 out of 48 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 29 third-party GitHubAction dependencies pinned
Info: 0 out of 18 pipCommand dependencies pinned