Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: railties/lib/rails/generators/rails/app/templates/Dockerfile.tt:17-19
Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: railties/lib/rails/generators/rails/app/templates/Dockerfile.tt:31-33
Info: Possibly incomplete results: error parsing shell code: > must be followed by a word: railties/lib/rails/generators/rails/app/templates/Dockerfile.tt:63-65
Info: Possibly incomplete results: error parsing shell code: > must be followed by a word: railties/lib/rails/generators/rails/app/templates/docker-entrypoint.tt:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/devcontainer-shellcheck.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/devcontainer-shellcheck.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/devcontainer-smoke-test.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/devcontainer-smoke-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/devcontainer-smoke-test.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/devcontainer-smoke-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/devcontainer-smoke-test.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/devcontainer-smoke-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/devcontainer-smoke-test.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/devcontainer-smoke-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/devcontainer-smoke-test.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/devcontainer-smoke-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/devcontainer-smoke-test.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/devcontainer-smoke-test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/devcontainer-smoke-test.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/devcontainer-smoke-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rail_inspector.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/rail_inspector.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rail_inspector.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/rail_inspector.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rails-new-docker.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/rails-new-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rails-new-docker.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/rails-new-docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rails-new-docker.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/rails-new-docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rails_releaser_tests.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/rails_releaser_tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rails_releaser_tests.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/rails_releaser_tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/rails/rails/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:5
Warn: containerImage not pinned by hash: railties/lib/rails/generators/rails/app/templates/Dockerfile.tt:12
Warn: containerImage not pinned by hash: railties/lib/rails/generators/rails/app/templates/Dockerfile.tt:29
Warn: containerImage not pinned by hash: railties/lib/rails/generators/rails/app/templates/Dockerfile.tt:104
Warn: containerImage not pinned by hash: railties/lib/rails/generators/rails/devcontainer/templates/devcontainer/Dockerfile.tt:3
Warn: containerImage not pinned by hash: railties/test/fixtures/Dockerfile.test:5
Warn: containerImage not pinned by hash: railties/test/fixtures/Dockerfile.test:21
Warn: containerImage not pinned by hash: railties/test/fixtures/Dockerfile.test:42
Warn: npmCommand not pinned by hash: railties/lib/rails/generators/rails/app/templates/Dockerfile.tt:47-50
Warn: downloadThenRun not pinned by hash: railties/lib/rails/generators/rails/app/templates/Dockerfile.tt:58
Info: 0 out of 7 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 12 third-party GitHubAction dependencies pinned
Info: 0 out of 8 containerImage dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned