Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/automated-release-tasks.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/automated-release-tasks.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/automated-release-tasks.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/automated-release-tasks.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-github-release.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/create-github-release.yml/dev?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-github-release.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/create-github-release.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release-branch.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/create-release-branch.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release-branch.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/create-release-branch.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/production-heartbeat.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/production-heartbeat.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/production-heartbeat.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/production-heartbeat.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/production-heartbeat.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/production-heartbeat.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/production-heartbeat.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/production-heartbeat.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-to-npm.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/publish-to-npm.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-to-npm.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/publish-to-npm.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-to-npm.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/publish-to-npm.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-to-npm.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/publish-to-npm.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-to-npm.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/publish-to-npm.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-to-npm.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/publish-to-npm.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-to-npm.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/publish-to-npm.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-to-npm.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/publish-to-npm.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:144: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:167: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:174: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:199: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:203: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:237: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:256: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:263: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-tests.yml:283: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/run-tests.yml/dev?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate-pr.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/forcedotcom/sfdx-scanner/validate-pr.yml/dev?enable=pin
Warn: npmCommand not pinned by hash: .github/workflows/production-heartbeat.yml:71
Warn: npmCommand not pinned by hash: .github/workflows/production-heartbeat.yml:72
Warn: npmCommand not pinned by hash: .github/workflows/production-heartbeat.yml:73
Warn: npmCommand not pinned by hash: .github/workflows/publish-to-npm.yml:84
Warn: npmCommand not pinned by hash: .github/workflows/run-tests.yml:212
Info: 0 out of 41 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 1 third-party GitHubAction dependencies pinned
Info: 0 out of 5 npmCommand dependencies pinned