Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:182: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: containerImage not pinned by hash: build/postgres-operator/Dockerfile:1: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal to registry.access.redhat.com/ubi8/ubi-minimal@sha256:33161cf5ec11ea13bfe60cad64f56a3aa4d893852e8ec44b2fd2a6b40cc38539
Info: 0 out of 28 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 2 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned