Warn: third-party GitHubAction not pinned by hash: .github/workflows/authors-and-third-party-notices.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/authors-and-third-party-notices.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/authors-and-third-party-notices.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/authors-and-third-party-notices.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/authors-and-third-party-notices.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/authors-and-third-party-notices.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bump-packages.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/bump-packages.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bump-packages.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/bump-packages.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bump-packages.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/bump-packages.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/check-pr-title.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/check-pr-title.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/check-pr-title.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/check-pr-title.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/codeql.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/merge-bump-packages-pr.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/merge-bump-packages-pr.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-compass.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/publish-compass.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-compass.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/publish-compass.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-packages.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/publish-packages.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-packages.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/publish-packages.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notes-labels.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/release-notes-labels.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notes-labels.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/release-notes-labels.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notes-labels.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/release-notes-labels.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notes-labels.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/release-notes-labels.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notes-labels.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/release-notes-labels.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-notes-labels.yaml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/release-notes-labels.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/start-beta.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/start-beta.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/start-beta.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/start-beta.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/start-ga.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/start-ga.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/start-ga.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/start-ga.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-electron.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-electron.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-electron.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-electron.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-electron.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb-js/compass/update-electron.yaml/main?enable=pin
Warn: containerImage not pinned by hash: .evergreen/connectivity-tests/Dockerfile:3
Warn: npmCommand not pinned by hash: .evergreen/connectivity-tests/Dockerfile:23
Warn: npmCommand not pinned by hash: .github/workflows/authors-and-third-party-notices.yaml:42
Warn: npmCommand not pinned by hash: .github/workflows/bump-packages.yaml:32
Warn: npmCommand not pinned by hash: .github/workflows/publish-compass.yaml:30
Warn: npmCommand not pinned by hash: .github/workflows/publish-packages.yaml:41
Warn: npmCommand not pinned by hash: .github/workflows/start-beta.yml:37
Warn: npmCommand not pinned by hash: .github/workflows/start-ga.yaml:37
Warn: npmCommand not pinned by hash: .github/workflows/update-electron.yaml:33
Info: 0 out of 18 GitHub-owned GitHubAction dependencies pinned
Info: 2 out of 14 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 6 out of 14 npmCommand dependencies pinned