Info: Possibly incomplete results: error parsing shell code: reached EOF without closing quote ": scripts/build_bytebase_aws.sh:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/backend-tests.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/backend-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/backend-tests.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/backend-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-push-action-image.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-action-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-push-action-image.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-action-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-push-action-image.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-action-image.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-push-action-image.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-action-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-push-action-image.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-action-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-push-action-image.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-action-image.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-push-release-image.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-release-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-push-release-image.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-release-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-push-release-image.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-release-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-push-release-image.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/build-push-release-image.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/comment-cherry-pick.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/comment-cherry-pick.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/comment-cherry-pick.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/comment-cherry-pick.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-tag-latest.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/docker-tag-latest.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-tag-latest.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/docker-tag-latest.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker-tag-latest.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/docker-tag-latest.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-tag-latest.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/docker-tag-latest.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-tag-latest.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/docker-tag-latest.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker-tag-latest.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/docker-tag-latest.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/draft-release.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/draft-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/draft-release.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/draft-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/frontend-tests.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/frontend-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/frontend-tests.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/frontend-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/frontend-tests.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/frontend-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/frontend-tests.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/frontend-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/frontend-tests.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/frontend-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/frontend-tests.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/frontend-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/golangci-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/proto-linter.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/proto-linter.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/proto-linter.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/proto-linter.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test_link.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/test_link.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test_link.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/bytebase/bytebase/test_link.yml/main?enable=pin
Warn: containerImage not pinned by hash: scripts/Dockerfile:1
Warn: containerImage not pinned by hash: scripts/Dockerfile:13
Warn: containerImage not pinned by hash: scripts/Dockerfile:37
Warn: containerImage not pinned by hash: scripts/Dockerfile.action:1
Warn: containerImage not pinned by hash: scripts/Dockerfile.action:11: pin your Docker image by updating alpine:3.22 to alpine:3.22@sha256:8a1f59ffb675680d47db6337b49d22281a139e9d709335b492be023728e11715
Warn: containerImage not pinned by hash: scripts/Dockerfile.action-debian:1
Warn: containerImage not pinned by hash: scripts/Dockerfile.action-debian:11: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:e5865e6858dacc255bead044a7f2d0ad8c362433cfaa5acefb670c1edf54dfef
Warn: containerImage not pinned by hash: scripts/Dockerfile.aws:1
Warn: containerImage not pinned by hash: scripts/Dockerfile.aws:13
Warn: containerImage not pinned by hash: scripts/Dockerfile.aws:37
Warn: npmCommand not pinned by hash: scripts/Dockerfile:4
Warn: npmCommand not pinned by hash: scripts/Dockerfile:61
Warn: npmCommand not pinned by hash: scripts/Dockerfile.aws:4
Warn: npmCommand not pinned by hash: scripts/Dockerfile.aws:61
Info: 0 out of 21 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 18 third-party GitHubAction dependencies pinned
Info: 0 out of 10 containerImage dependencies pinned
Info: 0 out of 4 npmCommand dependencies pinned