Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/close-no-repro.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/close-no-repro.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull_request.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/pull_request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull_request.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/pull_request.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull_request.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/pull_request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull_request.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/pull_request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull_request.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/pull_request.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull_request.yml:143: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/pull_request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull_request.yml:146: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/pull_request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull_request_close.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/pull_request_close.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/visual_regression_test.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/visual_regression_test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/weekly.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/weekly.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/weekly.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/weekly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/weekly.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/weekly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/weekly.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/fremtind/jokul/weekly.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:14
Warn: containerImage not pinned by hash: Dockerfile:28
Warn: containerImage not pinned by hash: Dockerfile:48
Warn: npmCommand not pinned by hash: Dockerfile:5
Info: 0 out of 24 GitHub-owned GitHubAction dependencies pinned
Info: 6 out of 11 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned