Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/docs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/docs.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/docs.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-please.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/release-please.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-please.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/release-please.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-please.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/release-please.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-please.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/release-please.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sonarcloud.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/sonarcloud.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sonarcloud.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/loopingz/webda.io/sonarcloud.yml/main?enable=pin
Warn: containerImage not pinned by hash: packages/aws/test/Dockerfile.txt:1: pin your Docker image by updating node:latest to node:latest@sha256:e7db48bc35ee8d2e8d1511dfe779d78076966bd101ab074ea2858da8d59efb7f
Warn: containerImage not pinned by hash: packages/core/Dockerfile:1
Warn: containerImage not pinned by hash: packages/core/Dockerfile.new:1: pin your Docker image by updating node:latest to node:latest@sha256:e7db48bc35ee8d2e8d1511dfe779d78076966bd101ab074ea2858da8d59efb7f
Warn: containerImage not pinned by hash: packages/core/test/Dockerfile:1
Warn: containerImage not pinned by hash: packages/core/test/Dockerfile.txt:1: pin your Docker image by updating node:latest to node:latest@sha256:e7db48bc35ee8d2e8d1511dfe779d78076966bd101ab074ea2858da8d59efb7f
Warn: containerImage not pinned by hash: packages/gcp/test/Dockerfile.txt:1: pin your Docker image by updating node:latest to node:latest@sha256:e7db48bc35ee8d2e8d1511dfe779d78076966bd101ab074ea2858da8d59efb7f
Warn: npmCommand not pinned by hash: packages/aws/test/Dockerfile.txt:10
Warn: npmCommand not pinned by hash: packages/core/Dockerfile.new:10
Warn: npmCommand not pinned by hash: packages/core/test/Dockerfile.txt:10
Warn: npmCommand not pinned by hash: packages/gcp/test/Dockerfile.txt:10
Info: 0 out of 11 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 9 third-party GitHubAction dependencies pinned
Info: 0 out of 6 containerImage dependencies pinned
Info: 0 out of 4 npmCommand dependencies pinned