Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:197: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:272: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/action.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/action.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/action.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/admin-i18n-validation.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/admin-i18n-validation.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/admin-i18n-validation.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/admin-i18n-validation.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-linear-issue-on-discussion.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/create-linear-issue-on-discussion.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-linear-issue-on-pr.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/create-linear-issue-on-pr.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-freshness-check.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-freshness-check.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-freshness-check.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-freshness-check.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-freshness-check.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-freshness-check.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:174: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:209: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:226: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:231: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:267: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:284: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:289: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:325: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:342: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:347: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:364: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:369: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-test.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-test.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-update-version.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/docs-update-version.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:150: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:176: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:221: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:226: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:231: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:257: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate-public-references.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/generate-public-references.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/oas-test.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/oas-test.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/oas-test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/oas-test.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notifications.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release-notifications.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/release.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot-this.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/snapshot-this.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot-this.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/snapshot-this.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot-this.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/snapshot-this.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot-this.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/snapshot-this.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-bot.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/stale-bot.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/team-labeler.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/team-labeler.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/team-labeler.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/team-labeler.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-cli-with-database.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/test-cli-with-database.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trigger-release.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/medusajs/medusa/trigger-release.yml/develop?enable=pin
Warn: downloadThenRun not pinned by hash: integration-tests/scripts/cli/get-products.sh:5
Warn: npmCommand not pinned by hash: .github/workflows/test-cli-with-database.yml:51
Info: 0 out of 44 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 34 third-party GitHubAction dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned