Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_GithubRunnerRegistration.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_GithubRunnerRegistration.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_GithubRunnerRegistration.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_GithubRunnerRegistration.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_GithubRunnerRegistration.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_GithubRunnerRegistration.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_apiserver.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_apiserver.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_apiserver.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_apiserver.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_apiserver.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_apiserver.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_operator.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_operator.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_operator.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_operator.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_operator.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_operator.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_operator.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_operator.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_runner.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_runner.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_runner.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_runner.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_runner.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/devjoes/github-runner-autoscaler/build_runner.yaml/master?enable=pin
Warn: containerImage not pinned by hash: GithubRunnerRegistration/GithubRunnerRegistration.Api/Dockerfile:3
Warn: containerImage not pinned by hash: GithubRunnerRegistration/GithubRunnerRegistration.Api/Dockerfile:11
Warn: containerImage not pinned by hash: GithubRunnerRegistration/GithubRunnerRegistration.Api/Dockerfile:23
Warn: containerImage not pinned by hash: GithubRunnerRegistration/GithubRunnerRegistration.Api/Dockerfile:26
Warn: containerImage not pinned by hash: apiserver/Dockerfile:1
Warn: containerImage not pinned by hash: apiserver/Dockerfile:5
Warn: containerImage not pinned by hash: apiserver/Dockerfile:25: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:6ec5aa99dc335666e79dc64e4a6c8b89c33a543a1967f20d360922a80dd21f02
Warn: containerImage not pinned by hash: examples/load-test/simple-app/Dockerfile:1: pin your Docker image by updating bash to bash@sha256:64defcbc5126c2d81122b4fb78a629a6d27068f0842c4a8302b8273415b12e30
Warn: containerImage not pinned by hash: operator/Dockerfile:1
Warn: containerImage not pinned by hash: operator/Dockerfile:19: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:6ec5aa99dc335666e79dc64e4a6c8b89c33a543a1967f20d360922a80dd21f02
Warn: containerImage not pinned by hash: runner/Dockerfile:1
Warn: containerImage not pinned by hash: runner/Dockerfile:7: pin your Docker image by updating myoung34/github-runner:latest to myoung34/github-runner:latest@sha256:4bcdc0a3c872735c2f6e15040baf024528f62a5928c4297dd2259194b4072954
Warn: nugetCommand not pinned by hash: GithubRunnerRegistration/GithubRunnerRegistration.Api/Dockerfile:16: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: GithubRunnerRegistration/GithubRunnerRegistration.Api/Dockerfile:17: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: goCommand not pinned by hash: apiserver/Dockerfile:14
Info: 0 out of 4 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 9 third-party GitHubAction dependencies pinned
Info: 0 out of 12 containerImage dependencies pinned
Info: 0 out of 2 nugetCommand dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned