Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-master.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/architect-community/microservices-demo/ci-master.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-master.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/architect-community/microservices-demo/ci-master.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-master.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/architect-community/microservices-demo/ci-master.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-master.yaml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/architect-community/microservices-demo/ci-master.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-pr.yaml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/architect-community/microservices-demo/ci-pr.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-pr.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/architect-community/microservices-demo/ci-pr.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-pr.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/architect-community/microservices-demo/ci-pr.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci-pr.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/architect-community/microservices-demo/ci-pr.yaml/master?enable=pin
Warn: containerImage not pinned by hash: src/adservice/Dockerfile:15
Warn: containerImage not pinned by hash: src/adservice/Dockerfile:28: pin your Docker image by updating openjdk:8-slim to openjdk:8-slim@sha256:19578a1e13b7a1e4cab9b227fb7b5d80e14665cf4024c6407d72ba89842a97ed
Warn: containerImage not pinned by hash: src/cartservice/src/Dockerfile:16
Warn: containerImage not pinned by hash: src/cartservice/src/Dockerfile:24: pin your Docker image by updating mcr.microsoft.com/dotnet/runtime-deps:6.0.5-alpine3.14-amd64 to mcr.microsoft.com/dotnet/runtime-deps:6.0.5-alpine3.14-amd64@sha256:58709e77dda40292bafe04a2d4b16d0fbe32511adc4bb41e12daaacc0afcf3fc
Warn: containerImage not pinned by hash: src/cartservice/src/Dockerfile.debug:15
Warn: containerImage not pinned by hash: src/cartservice/src/Dockerfile.debug:21
Warn: containerImage not pinned by hash: src/cartservice/src/Dockerfile.debug:25
Warn: containerImage not pinned by hash: src/checkoutservice/Dockerfile:15
Warn: containerImage not pinned by hash: src/checkoutservice/Dockerfile:30
Warn: containerImage not pinned by hash: src/currencyservice/Dockerfile:15
Warn: containerImage not pinned by hash: src/currencyservice/Dockerfile:17
Warn: containerImage not pinned by hash: src/currencyservice/Dockerfile:32
Warn: containerImage not pinned by hash: src/emailservice/Dockerfile:15
Warn: containerImage not pinned by hash: src/emailservice/Dockerfile:17
Warn: containerImage not pinned by hash: src/emailservice/Dockerfile:28
Warn: containerImage not pinned by hash: src/frontend/Dockerfile:15
Warn: containerImage not pinned by hash: src/frontend/Dockerfile:29
Warn: containerImage not pinned by hash: src/loadgenerator/Dockerfile:15
Warn: containerImage not pinned by hash: src/loadgenerator/Dockerfile:17
Warn: containerImage not pinned by hash: src/loadgenerator/Dockerfile:27
Warn: containerImage not pinned by hash: src/paymentservice/Dockerfile:15
Warn: containerImage not pinned by hash: src/paymentservice/Dockerfile:17
Warn: containerImage not pinned by hash: src/paymentservice/Dockerfile:32
Warn: containerImage not pinned by hash: src/productcatalogservice/Dockerfile:15
Warn: containerImage not pinned by hash: src/productcatalogservice/Dockerfile:29
Warn: containerImage not pinned by hash: src/recommendationservice/Dockerfile:15: pin your Docker image by updating python:3.7-slim to python:3.7-slim@sha256:b53f496ca43e5af6994f8e316cf03af31050bf7944e0e4a308ad86c001cf028b
Warn: containerImage not pinned by hash: src/shippingservice/Dockerfile:15
Warn: containerImage not pinned by hash: src/shippingservice/Dockerfile:29
Warn: nugetCommand not pinned by hash: src/cartservice/src/Dockerfile:19: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: src/cartservice/src/Dockerfile.debug:18: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: npmCommand not pinned by hash: src/currencyservice/Dockerfile:30
Warn: pipCommand not pinned by hash: src/emailservice/Dockerfile:26
Warn: pipCommand not pinned by hash: src/loadgenerator/Dockerfile:25
Warn: npmCommand not pinned by hash: src/paymentservice/Dockerfile:30
Warn: pipCommand not pinned by hash: src/recommendationservice/Dockerfile:30
Warn: goCommand not pinned by hash: .github/workflows/install-dependencies.sh:52
Info: 0 out of 8 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 28 containerImage dependencies pinned
Info: 0 out of 2 nugetCommand dependencies pinned
Info: 0 out of 2 npmCommand dependencies pinned
Info: 0 out of 3 pipCommand dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned