Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: deploy/images/windows/Dockerfile:19-28
Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: deploy/images/windows/Dockerfile:35-44
Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: deploy/images/windows/Dockerfile:51-63
Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: deploy/images/windows/Dockerfile:70-79
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-policy.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build-policy.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-policy.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build-policy.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-policy.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build-policy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-policy.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build-policy.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-policy.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build-policy.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-policy.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build-policy.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-policy.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build-policy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/build.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/check.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/check.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/check.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/AliyunContainerService/terway/release.yml/main?enable=pin
Warn: containerImage not pinned by hash: deploy/images/policy/Dockerfile:2
Warn: containerImage not pinned by hash: deploy/images/terway-controlplane/Dockerfile:4
Warn: containerImage not pinned by hash: deploy/images/terway-controlplane/Dockerfile:6
Warn: containerImage not pinned by hash: deploy/images/terway-controlplane/Dockerfile:21
Warn: containerImage not pinned by hash: deploy/images/terway/Dockerfile:9
Warn: containerImage not pinned by hash: deploy/images/terway/Dockerfile:10
Warn: containerImage not pinned by hash: deploy/images/terway/Dockerfile:11
Warn: containerImage not pinned by hash: deploy/images/terway/Dockerfile:12
Warn: containerImage not pinned by hash: deploy/images/terway/Dockerfile:13
Warn: containerImage not pinned by hash: deploy/images/terway/Dockerfile:15
Warn: containerImage not pinned by hash: deploy/images/terway/Dockerfile:31
Warn: containerImage not pinned by hash: deploy/images/windows/Dockerfile:8
Warn: containerImage not pinned by hash: deploy/images/windows/Dockerfile:130
Warn: downloadThenRun not pinned by hash: tests/kind/run.sh:16
Info: 0 out of 17 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 13 third-party GitHubAction dependencies pinned
Info: 1 out of 1 goCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 1 out of 14 containerImage dependencies pinned