Info: Possibly incomplete results: error parsing shell code: parameter expansion requires a literal: .devcontainer/scripts/zsh_dotnet_completion.sh:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:228: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:231: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:258: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:138: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:187: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:192: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:195: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:210: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:218: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/commands.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/commands.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/commands.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/commands.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/commands.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/commands.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/commands.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/commands.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/commands.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/commands.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/commands.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/fable-compiler/Fable/commands.yml/main?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:21: pin your Docker image by updating mcr.microsoft.com/devcontainers/base:debian to mcr.microsoft.com/devcontainers/base:debian@sha256:b3fd61ae07a1ebd211cac645c758f4018688a86e2c9b596a6c862ca89b0a668d
Warn: downloadThenRun not pinned by hash: .devcontainer/Dockerfile:40
Warn: downloadThenRun not pinned by hash: .devcontainer/Dockerfile:63
Warn: downloadThenRun not pinned by hash: .devcontainer/Dockerfile:76
Warn: downloadThenRun not pinned by hash: .devcontainer/Dockerfile:84
Warn: downloadThenRun not pinned by hash: .devcontainer/Dockerfile:89
Warn: pipCommand not pinned by hash: .github/workflows/build.yml:158
Warn: nugetCommand not pinned by hash: .github/workflows/build.yml:45: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Info: 0 out of 33 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 2 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 0 out of 5 downloadThenRun dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 1 nugetCommand dependencies pinned