Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-images.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/build-images.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-images.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/build-images.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-images.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/build-images.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-images.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/build-images.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-testing.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/chart-testing.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-testing.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/chart-testing.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-testing.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/chart-testing.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-testing.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/chart-testing.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-testing.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/chart-testing.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:182: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:188: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:216: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:218: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:237: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:239: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/fossa.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/fossa.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/fossa.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/fossa.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/artifacthub/hub/release.yml/master?enable=pin
Warn: containerImage not pinned by hash: .gitpod/Dockerfile:1: pin your Docker image by updating gitpod/workspace-postgres to gitpod/workspace-postgres@sha256:f22cc0f10d0f70ee8e02a50d679880eec30bbedbc274f6c9de80e56b9f3f8e40
Warn: containerImage not pinned by hash: cmd/ah/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/ah/Dockerfile:13: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: cmd/hub/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/hub/Dockerfile:11
Warn: containerImage not pinned by hash: cmd/hub/Dockerfile:20
Warn: containerImage not pinned by hash: cmd/hub/Dockerfile:28
Warn: containerImage not pinned by hash: cmd/hub/Dockerfile:37: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: cmd/scanner/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/scanner/Dockerfile:11
Warn: containerImage not pinned by hash: cmd/scanner/Dockerfile:16: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: cmd/tracker/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/tracker/Dockerfile:16
Warn: containerImage not pinned by hash: cmd/tracker/Dockerfile:24: pin your Docker image by updating debian:bullseye-slim to debian:bullseye-slim@sha256:fdd75562fdcde1039c2480a1ea1cd2cf03b18b6e4cb551cabb03bde66ade8a5d
Warn: containerImage not pinned by hash: database/migrations/Dockerfile:2
Warn: containerImage not pinned by hash: database/migrations/Dockerfile:7: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: database/tests/Dockerfile-db-tests:2
Warn: containerImage not pinned by hash: database/tests/Dockerfile-db-tests:7: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: database/tests/Dockerfile-postgres:2
Warn: containerImage not pinned by hash: database/tests/Dockerfile-postgres:11: pin your Docker image by updating postgres:13 to postgres:13@sha256:7dad293647281f6a0f0b7b9b7adc3c27775d2adc821d8ccd9d2ff72ef503a1c8
Warn: downloadThenRun not pinned by hash: cmd/scanner/Dockerfile:13
Warn: goCommand not pinned by hash: database/migrations/Dockerfile:4
Warn: goCommand not pinned by hash: database/tests/Dockerfile-db-tests:4
Info: 0 out of 32 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 15 third-party GitHubAction dependencies pinned
Info: 0 out of 20 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 0 out of 2 goCommand dependencies pinned