Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:178: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:204: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: containerImage not pinned by hash: build/postgres-operator/Dockerfile:1: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal to registry.access.redhat.com/ubi8/ubi-minimal@sha256:b2a1bec3dfbc7a14a1d84d98934dfe8fdde6eb822a211286601cf109cbccb075
Info: 0 out of 28 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 2 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned