Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cffconvert.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/cffconvert.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cffconvert.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/cffconvert.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gradle-wrapper-validation.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/gradle-wrapper-validation.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gradle-wrapper-validation.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/gradle-wrapper-validation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ios.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/ios.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ios.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/ios.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labeler.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/labeler.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux_training.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux_training.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux_training.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/linux_training.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux_training.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:170: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:186: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:215: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:225: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/macos_coreml.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/macos_coreml.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/macos_coreml.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/macos_coreml.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr_checks.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/pr_checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr_checks.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/pr_checks.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr_checks.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/pr_checks.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr_checks.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/pr_checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-c-apidocs.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-c-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-c-apidocs.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-c-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-csharp-apidocs.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-csharp-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-csharp-apidocs.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-csharp-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-java-apidocs.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-java-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-java-apidocs.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-java-apidocs.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-java-apidocs.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-java-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-java-apidocs.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-java-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-js-apidocs.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-js-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-js-apidocs.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-js-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-js-apidocs.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-js-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-objectivec-apidocs.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-objectivec-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-objectivec-apidocs.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-objectivec-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-python-apidocs.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-python-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-python-apidocs.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-python-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/stale.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/title-only-labeler.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/title-only-labeler.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_build_x64_asan.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_build_x64_asan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_build_x64_asan.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_build_x64_asan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_build_x64_asan.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_build_x64_asan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_cuda.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_cuda.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_cuda.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_cuda.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_cuda.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_cuda.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_cuda.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_cuda.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_cuda.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_cuda.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_cuda.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_cuda.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_cuda.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_cuda.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_dml.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_dml.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_dml.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_dml.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_dml.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_dml.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_dml.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_dml.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_dml.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_dml.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_dml.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_dml.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_dml.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_dml.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_openvino.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_openvino.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_openvino.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_openvino.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_openvino.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_openvino.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_tensorrt.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_tensorrt.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_tensorrt.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_tensorrt.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_tensorrt.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_tensorrt.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:144: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:182: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:188: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:204: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:209: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:226: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_webgpu.yml:244: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_webgpu.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_debug_build_x64_debug.yml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_debug_build_x64_debug.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_build_x64_release.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_dnnl_build_x64_release.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_dnnl_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_ep_generic_interface_build_x64_release_ep_generic_interface.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_vitisai_build_x64_release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_vitisai_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_vitisai_build_x64_release.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_vitisai_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_vitisai_build_x64_release.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_vitisai_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_vitisai_build_x64_release.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_vitisai_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_vitisai_build_x64_release.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_vitisai_build_x64_release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_x64_release_vitisai_build_x64_release.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_vitisai_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_vitisai_build_x64_release.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_vitisai_build_x64_release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x64_release_xnnpack.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x64_release_xnnpack.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows_x86.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows_x86.yml/main?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:8
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.cuda:12
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.cuda:64
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.jetson:10
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.migraphx:8: pin your Docker image by updating rocm/pytorch:rocm6.2.3_ubuntu22.04_py3.10_pytorch_release_2.3.0 to rocm/pytorch:rocm6.2.3_ubuntu22.04_py3.10_pytorch_release_2.3.0@sha256:54422bee895f9e44bc5257ab03011aae532c5b7cfa39dda00a3000c46db81239
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.openvino:10
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.openvino:42
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.rocm:8: pin your Docker image by updating rocm/pytorch:rocm6.2.3_ubuntu22.04_py3.10_pytorch_release_2.3.0 to rocm/pytorch:rocm6.2.3_ubuntu22.04_py3.10_pytorch_release_2.3.0@sha256:54422bee895f9e44bc5257ab03011aae532c5b7cfa39dda00a3000c46db81239
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.source:7: pin your Docker image by updating mcr.microsoft.com/cbl-mariner/base/python:3 to mcr.microsoft.com/cbl-mariner/base/python:3@sha256:c2323ff52ac04ab229de3e9d703333194641fb2f8d45d72930a0ff653e12f8ba
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.source:18: pin your Docker image by updating mcr.microsoft.com/cbl-mariner/base/python:3 to mcr.microsoft.com/cbl-mariner/base/python:3@sha256:c2323ff52ac04ab229de3e9d703333194641fb2f8d45d72930a0ff653e12f8ba
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.tensorrt:9
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.vitisai:7: pin your Docker image by updating xilinx/vitis-ai-cpu:1.3.598 to xilinx/vitis-ai-cpu:1.3.598@sha256:cb502f96f071126f0efc90ee36df90cd0dba5b285891aca05c91dd0d91a74a09
Warn: containerImage not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:3: pin your Docker image by updating rocm/pytorch:rocm4.3.1_ubuntu18.04_py3.6_pytorch_1.9.0 to rocm/pytorch:rocm4.3.1_ubuntu18.04_py3.6_pytorch_1.9.0@sha256:7742f1f1df2eaa58f1e183b9a3ceb7b151f782ab7e9df2a72c69927a48f84aee
Warn: containerImage not pinned by hash: tools/android_custom_build/Dockerfile:7: pin your Docker image by updating ubuntu:20.04 to ubuntu:20.04@sha256:8e5c4f0285ecbb4ead070431d29b576a530d3166df73ec44affc1cd27555141b
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_cpu:1
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_cuda:7
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:1
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda11_8_tensorrt8_6:10
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda11_8_tensorrt8_6:41
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0:10
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0:49
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:10
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:52
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2004_gpu:11
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2004_gpu:57
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_ffmpeg:11
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_ffmpeg:64
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_opencv:11
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_opencv:59
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:64
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:64
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_openvino:2
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:57
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/aarch64/default/cpu/Dockerfile:5
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/aarch64/python/cpu/Dockerfile:1
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/default/cpu/Dockerfile:5
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/default/cuda11/Dockerfile:5
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/default/cuda12/Dockerfile:5
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/python/cpu/Dockerfile:1
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/python/cuda/Dockerfile:7
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/migraphx-ci-pipeline-env.Dockerfile:2: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:ed1544e454989078f5dec1bfdabd8c5cc9c48e0705d07b678ab6ae3fb61952d2
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/rocm-ci-pipeline-env.Dockerfile:2: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:ed1544e454989078f5dec1bfdabd8c5cc9c48e0705d07b678ab6ae3fb61952d2
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.cuda:49-61
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.cuda:49-61
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.cuda:95-106
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.jetson:29
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.jetson:30
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.jetson:31
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.migraphx:21-26
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.openvino:27
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.openvino:29
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.source:21
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.source:21
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:52
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:55-58
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:113
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:120-135
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:137
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:139
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:140
Warn: pipCommand not pinned by hash: tools/android_custom_build/Dockerfile:45
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda11_8_tensorrt8_6:26
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda11_8_tensorrt8_6:27
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0:17
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0:18
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:17
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:18
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:49
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2004_gpu:28
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_ffmpeg:28
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_opencv:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:31
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:109
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:31
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:109
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:31
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:103
Warn: downloadThenRun not pinned by hash: tools/ci_build/github/linux/docker/migraphx-ci-pipeline-env.Dockerfile:74-78
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/migraphx-ci-pipeline-env.Dockerfile:95
Warn: downloadThenRun not pinned by hash: tools/ci_build/github/linux/docker/rocm-ci-pipeline-env.Dockerfile:71-75
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/rocm-ci-pipeline-env.Dockerfile:92-98
Warn: nugetCommand not pinned by hash: csharp/test/Microsoft.ML.OnnxRuntime.EndToEndTests/runtest.sh:29: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: downloadThenRun not pinned by hash: dockerfiles/scripts/install_common_deps.sh:14
Warn: pipCommand not pinned by hash: dockerfiles/scripts/install_common_deps.sh:18
Warn: pipCommand not pinned by hash: dockerfiles/scripts/install_common_deps.sh:19
Warn: pipCommand not pinned by hash: dockerfiles/scripts/install_common_deps.sh:20
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/tensorrt/perf/mem_test/run.sh:119
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/tensorrt/perf/perf.sh:56
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/tensorrt/perf/perf.sh:57
Warn: downloadThenRun not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:73
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:97
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:98
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:100
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:103
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:114
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:121
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:132
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:260
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:273
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:341
Warn: downloadThenRun not pinned by hash: onnxruntime/python/tools/transformers/models/stable_diffusion/benchmark_flux.sh:33
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/stable_diffusion/benchmark_flux.sh:58
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/stable_diffusion/benchmark_flux.sh:70
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/stable_diffusion/benchmark_flux.sh:90
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/stable_diffusion/benchmark_flux.sh:91
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/run_benchmark.sh:94
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/run_benchmark.sh:96
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/run_benchmark.sh:98
Warn: pipCommand not pinned by hash: tools/ci_build/github/android/build_aar_and_copy_artifacts.sh:26
Warn: downloadThenRun not pinned by hash: tools/ci_build/github/linux/docker/scripts/install_rust.sh:5
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/ort_minimal/build_full_ort_and_create_ort_files.sh:11
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/ort_minimal/build_full_ort_and_create_ort_files.sh:33
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/ort_minimal/build_minimal_ort_and_run_tests.sh:68
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/ort_minimal/nnapi_minimal_build_minimal_ort_and_run_tests.sh:16
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/run_python_tests.sh:45
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/run_python_tests.sh:47
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/run_python_tests.sh:49
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/run_python_tests.sh:52
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/test_custom_ops_pytorch_export.sh:3
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/test_custom_ops_pytorch_export.sh:5
Warn: pipCommand not pinned by hash: tools/scripts/python_test.sh:15
Warn: pipCommand not pinned by hash: tools/scripts/python_test.sh:20
Warn: pipCommand not pinned by hash: .github/workflows/lint.yml:61
Warn: pipCommand not pinned by hash: .github/workflows/lint.yml:96
Warn: pipCommand not pinned by hash: .github/workflows/linux_training.yml:23
Warn: pipCommand not pinned by hash: .github/workflows/mac.yml:77
Warn: pipCommand not pinned by hash: .github/workflows/pr_checks.yml:44
Warn: pipCommand not pinned by hash: .github/workflows/pr_checks.yml:45
Warn: nugetCommand not pinned by hash: .github/workflows/publish-csharp-apidocs.yml:38: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/publish-csharp-apidocs.yml:39: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: pipCommand not pinned by hash: .github/workflows/publish-python-apidocs.yml:35
Warn: pipCommand not pinned by hash: .github/workflows/publish-python-apidocs.yml:37
Warn: pipCommand not pinned by hash: .github/workflows/publish-python-apidocs.yml:38
Info: 0 out of 143 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 22 third-party GitHubAction dependencies pinned
Info: 0 out of 45 containerImage dependencies pinned
Info: 9 out of 94 pipCommand dependencies pinned
Info: 0 out of 6 downloadThenRun dependencies pinned
Info: 0 out of 3 nugetCommand dependencies pinned
Info: 2 out of 2 npmCommand dependencies pinned