Warn: third-party GitHubAction not pinned by hash: .github/workflows/authors-and-third-party-notices.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/authors-and-third-party-notices.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/authors-and-third-party-notices.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/authors-and-third-party-notices.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/authors-and-third-party-notices.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/authors-and-third-party-notices.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bump-packages.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/bump-packages.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bump-packages.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/bump-packages.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bump-packages.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/bump-packages.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/codeql.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/merge-bump-packages-pr.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/merge-bump-packages-pr.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-compass.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/publish-compass.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-compass.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/publish-compass.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-packages.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/publish-packages.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-packages.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/publish-packages.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/start-beta.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/start-beta.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/start-beta.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/start-beta.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/start-ga.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/start-ga.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/start-ga.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/start-ga.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-installers.yml:188: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/test-installers.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-installers.yml:190: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/test-installers.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-installers.yml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/test-installers.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-installers.yml:211: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/test-installers.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-installers.yml:220: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/test-installers.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-installers.yml:253: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/test-installers.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-electron.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-electron.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-electron.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-electron.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-electron.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-electron.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-eslint.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-eslint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-eslint.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-eslint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-eslint.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-eslint.yaml/main?enable=pin
Warn: containerImage not pinned by hash: .evergreen/connectivity-tests/Dockerfile:3
Warn: npmCommand not pinned by hash: .evergreen/connectivity-tests/Dockerfile:23
Warn: npmCommand not pinned by hash: .github/workflows/authors-and-third-party-notices.yaml:48
Warn: npmCommand not pinned by hash: .github/workflows/bump-packages.yaml:39
Warn: npmCommand not pinned by hash: .github/workflows/publish-compass.yaml:33
Warn: npmCommand not pinned by hash: .github/workflows/publish-packages.yaml:44
Warn: npmCommand not pinned by hash: .github/workflows/start-beta.yml:41
Warn: npmCommand not pinned by hash: .github/workflows/start-ga.yaml:41
Warn: npmCommand not pinned by hash: .github/workflows/test-installers.yml:230
Warn: npmCommand not pinned by hash: .github/workflows/update-electron.yaml:37
Warn: npmCommand not pinned by hash: .github/workflows/update-eslint.yaml:37
Info: 0 out of 25 GitHub-owned GitHubAction dependencies pinned
Info: 11 out of 16 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 8 out of 18 npmCommand dependencies pinned