Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/closed_references.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/closed_references.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/closed_references.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/closed_references.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/closed_references.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/closed_references.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/conventional_commits.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/conventional_commits.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/conventional_commits.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/conventional_commits.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/conventional_commits.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/conventional_commits.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-ci.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/docker-ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-ci.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/docker-ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-ci.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/docker-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/docker-publish.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-publish.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/docker-publish.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labels.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/labels.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/labels.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/labels.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/licenses.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/licenses.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/licenses.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/licenses.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/licenses.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/licenses.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/ory/sdk/stale.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:2: pin your Docker image by updating openjdk:21-bookworm to openjdk:21-bookworm@sha256:f3c2871187043c46f1053dbdbba456032624c9e3e328e760e09e744710127a0b
Warn: downloadThenRun not pinned by hash: Dockerfile:56
Warn: npmCommand not pinned by hash: Dockerfile:79
Warn: npmCommand not pinned by hash: Dockerfile:80
Warn: downloadThenRun not pinned by hash: Dockerfile:86-93
Warn: downloadThenRun not pinned by hash: Dockerfile:103
Warn: npmCommand not pinned by hash: scripts/release.sh:111
Warn: npmCommand not pinned by hash: scripts/release.sh:120
Warn: pipCommand not pinned by hash: scripts/release.sh:175
Warn: npmCommand not pinned by hash: scripts/test.sh:13
Warn: npmCommand not pinned by hash: scripts/test.sh:20
Warn: pipCommand not pinned by hash: scripts/test.sh:41
Warn: pipCommand not pinned by hash: scripts/test.sh:41
Info: 0 out of 7 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 10 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 0 out of 3 downloadThenRun dependencies pinned
Info: 0 out of 6 npmCommand dependencies pinned
Info: 0 out of 3 pipCommand dependencies pinned