⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:214: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:216: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:222: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:257: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:259: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:272: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/build.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/codeql.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/codeql.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/codeql.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/codeql.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/codeql.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deps-review.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/deps-review.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deps-review.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/deps-review.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/qodana.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/qodana.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/qodana.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/qodana.yml/master?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/qodana.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/qodana.yml/master?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/qodana.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/json-api-dotnet/JsonApiDotNetCore/qodana.yml/master?enable=pin
⚠️
Warn: nugetCommand not pinned by hash: .github/workflows/build.yml:229: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
⚠️
Warn: nugetCommand not pinned by hash: .github/workflows/build.yml:63: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
⚠️
Warn: nugetCommand not pinned by hash: .github/workflows/qodana.yml:39: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
ℹ️
Info: 0 out of 20 GitHub-owned GitHubAction dependencies pinned
ℹ️
Info: 0 out of 8 third-party GitHubAction dependencies pinned
ℹ️
Info: 0 out of 3 nugetCommand dependencies pinned