Info: Possibly incomplete results: error parsing shell code: [ must follow a name: .github/workflows/build-&-publish-docker-image.yml:218
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/automate-add-issue-in-project.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/automate-add-issue-in-project.yaml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/backup.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/backup.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/backup.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/backup.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/benchmark.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/benchmark.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/benchmark.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:147: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:232: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:238: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:253: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-&-publish-docker-image.yml:270: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-&-publish-docker-image.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-for-conductor-testing.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-for-conductor-testing.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-for-conductor-testing.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-for-conductor-testing.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-for-conductor-testing.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/build-for-conductor-testing.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cicd.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/cicd.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cicd.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/cicd.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/codeql-analysis.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/codeql-analysis.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/codeql-analysis.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/codeql-analysis.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/codeql-analysis.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/config-change-0helm-pr.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/config-change-0helm-pr.yaml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/config-change-0helm-pr.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/config-change-0helm-pr.yaml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/config-change-0helm-pr.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/config-change-0helm-pr.yaml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/config-change-0helm-pr.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/config-change-0helm-pr.yaml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/config_change_alert.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/config_change_alert.yaml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/config_change_alert.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/config_change_alert.yaml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dev-1.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/dev-1.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dev-1.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/dev-1.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gosdk.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/gosdk.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gosdk.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/gosdk.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gosdk.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/gosdk.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/tests.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/tests.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/tests.yml/staging?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/tests.yml/staging?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/0chain/blobber/tests.yml/staging?enable=pin
Warn: containerImage not pinned by hash: docker.aws/build.blobber/Dockerfile:2
Warn: containerImage not pinned by hash: docker.aws/build.blobber/Dockerfile:38: pin your Docker image by updating golang:1.19-alpine3.17 to golang:1.19-alpine3.17@sha256:d6ac032bc70047adda516fc0937aa089ba3d3a03115f7ecdc38ce178091ed75b
Warn: containerImage not pinned by hash: docker.aws/build.validator/Dockerfile:2
Warn: containerImage not pinned by hash: docker.aws/build.validator/Dockerfile:38: pin your Docker image by updating golang:1.19-alpine3.17 to golang:1.19-alpine3.17@sha256:d6ac032bc70047adda516fc0937aa089ba3d3a03115f7ecdc38ce178091ed75b
Warn: containerImage not pinned by hash: docker.local/Dockerfile:1
Warn: containerImage not pinned by hash: docker.local/Dockerfile:25: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f
Warn: containerImage not pinned by hash: docker.local/Dockerfile.dev:1
Warn: containerImage not pinned by hash: docker.local/Dockerfile.dev:24: pin your Docker image by updating golang:1.19-alpine3.17 to golang:1.19-alpine3.17@sha256:d6ac032bc70047adda516fc0937aa089ba3d3a03115f7ecdc38ce178091ed75b
Warn: containerImage not pinned by hash: docker.local/Dockerfile.swagger:2
Warn: containerImage not pinned by hash: docker.local/Dockerfile.swagger:17
Warn: containerImage not pinned by hash: docker.local/IntegrationTestsBlobber.Dockerfile:1
Warn: containerImage not pinned by hash: docker.local/IntegrationTestsBlobber.Dockerfile:22: pin your Docker image by updating golang:1.19-alpine3.17 to golang:1.19-alpine3.17@sha256:d6ac032bc70047adda516fc0937aa089ba3d3a03115f7ecdc38ce178091ed75b
Warn: containerImage not pinned by hash: docker.local/IntegrationTestsValidator.Dockerfile:1
Warn: containerImage not pinned by hash: docker.local/IntegrationTestsValidator.Dockerfile:23: pin your Docker image by updating golang:1.19-alpine3.17 to golang:1.19-alpine3.17@sha256:d6ac032bc70047adda516fc0937aa089ba3d3a03115f7ecdc38ce178091ed75b
Warn: containerImage not pinned by hash: docker.local/ValidatorDockerfile:1
Warn: containerImage not pinned by hash: docker.local/ValidatorDockerfile:23: pin your Docker image by updating golang:1.19-alpine3.17 to golang:1.19-alpine3.17@sha256:d6ac032bc70047adda516fc0937aa089ba3d3a03115f7ecdc38ce178091ed75b
Warn: containerImage not pinned by hash: docker.local/ValidatorDockerfile.dev:1
Warn: containerImage not pinned by hash: docker.local/ValidatorDockerfile.dev:22: pin your Docker image by updating golang:1.19-alpine3.17 to golang:1.19-alpine3.17@sha256:d6ac032bc70047adda516fc0937aa089ba3d3a03115f7ecdc38ce178091ed75b
Warn: containerImage not pinned by hash: docker.local/base.Dockerfile:1
Warn: containerImage not pinned by hash: docker.local/blobber.Dockerfile:3
Warn: containerImage not pinned by hash: docker.local/blobber.Dockerfile:24: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f
Warn: containerImage not pinned by hash: docker.local/docker-clean/Dockerfile:6: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: docker.local/validator.Dockerfile:3
Warn: containerImage not pinned by hash: docker.local/validator.Dockerfile:26: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f
Warn: pipCommand not pinned by hash: .github/workflows/backup.yml:29
Info: 0 out of 23 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 18 third-party GitHubAction dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 24 containerImage dependencies pinned