Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/auto-label.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/auto-label.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-sync.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/chart-sync.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-sync.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/chart-sync.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github_pagerduty_score_calculation.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/github_pagerduty_score_calculation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github_pagerduty_score_calculation.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/github_pagerduty_score_calculation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/multiarch_new.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/multiarch_new.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/multiarch_new.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/multiarch_new.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pager-duty-issue-escalate.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/pager-duty-issue-escalate.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-issue-validator.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/pr-issue-validator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/sync.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sync.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/sync.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: DockerfileEA:1
Warn: containerImage not pinned by hash: sample-docker-templates/django/Dockerfile:4: pin your Docker image by updating python:3.8 to python:3.8@sha256:d411270700143fa2683cc8264d9fa5d3279fd3b6afff62ae81ea2f9d070e390c
Warn: containerImage not pinned by hash: sample-docker-templates/flask/Dockerfile:2: pin your Docker image by updating python:3.8 to python:3.8@sha256:d411270700143fa2683cc8264d9fa5d3279fd3b6afff62ae81ea2f9d070e390c
Warn: containerImage not pinned by hash: sample-docker-templates/go/Dockerfile:3
Warn: containerImage not pinned by hash: sample-docker-templates/go/Dockerfile:24: pin your Docker image by updating alpine:3.7 to alpine:3.7@sha256:8421d9a84432575381bfabd248f1eb56f3aa21d9d7cd2511583c68c9b7511d10
Warn: containerImage not pinned by hash: sample-docker-templates/java/Gradle_Dockerfile:4
Warn: containerImage not pinned by hash: sample-docker-templates/java/Gradle_Dockerfile:18: pin your Docker image by updating openjdk:8-jre-slim to openjdk:8-jre-slim@sha256:53186129237fbb8bc0a12dd36da6761f4c7a2a20233c20d4eb0d497e4045a4f5
Warn: containerImage not pinned by hash: sample-docker-templates/java/Maven_Dockerfile:4
Warn: containerImage not pinned by hash: sample-docker-templates/java/Maven_Dockerfile:24: pin your Docker image by updating openjdk:8-jre-alpine to openjdk:8-jre-alpine@sha256:f362b165b870ef129cbe730f29065ff37399c0aa8bcab3e44b51c302938c9193
Warn: containerImage not pinned by hash: sample-docker-templates/kotlin/Dockerfile:2: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: sample-docker-templates/php/Apache_Dockerfile:2: pin your Docker image by updating php:7-apache to php:7-apache@sha256:c9d7e608f73832673479770d66aacc8100011ec751d1905ff63fae3fe2e0ca6d
Warn: containerImage not pinned by hash: sample-docker-templates/php/Nginx_Dockerfile:2: pin your Docker image by updating ubuntu:16.04 to ubuntu:16.04@sha256:1f1a2d56de1d604801a9671f301190704c25d604a416f59e03c04f5c6ffee0d6
Warn: containerImage not pinned by hash: sample-docker-templates/php/php7.4/Dockerfile:1: pin your Docker image by updating ubuntu:20.04 to ubuntu:20.04@sha256:8feb4d8ca5354def3d8fce243717141ce31e2c428701f6682bd2fafe15388214
Warn: containerImage not pinned by hash: sample-docker-templates/react/Dockerfile:4
Warn: containerImage not pinned by hash: sample-docker-templates/react/Dockerfile:23: pin your Docker image by updating nginx:stable-alpine to nginx:stable-alpine@sha256:aed99734248e851764f1f2146835ecad42b5f994081fa6631cc5d79240891ec9
Warn: containerImage not pinned by hash: sample-docker-templates/rust/Dockerfile:2: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: goCommand not pinned by hash: Dockerfile:3-6
Warn: goCommand not pinned by hash: DockerfileEA:3-6
Warn: pipCommand not pinned by hash: sample-docker-templates/django/Dockerfile:30
Warn: pipCommand not pinned by hash: sample-docker-templates/flask/Dockerfile:30
Warn: npmCommand not pinned by hash: sample-docker-templates/node/Dockerfile:31
Warn: npmCommand not pinned by hash: sample-docker-templates/node/Dockerfile:32
Warn: npmCommand not pinned by hash: sample-docker-templates/react/Dockerfile:13
Warn: downloadThenRun not pinned by hash: tests/integrationTesting/create-test-env.sh:22
Warn: downloadThenRun not pinned by hash: tests/integrationTesting/create-test-env.sh:63
Warn: goCommand not pinned by hash: vendor/github.com/go-git/go-git/v5/oss-fuzz.sh:20
Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10
Warn: goCommand not pinned by hash: vendor/google.golang.org/grpc/regenerate.sh:35
Warn: goCommand not pinned by hash: vendor/google.golang.org/grpc/vet.sh:37
Warn: pipCommand not pinned by hash: .github/workflows/create-release.yml:77
Warn: goCommand not pinned by hash: .github/workflows/enterprise-repo-sync.yaml:41
Warn: pipCommand not pinned by hash: .github/workflows/multiarch_new.yaml:25
Info: 0 out of 10 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 2 out of 19 containerImage dependencies pinned
Info: 1 out of 8 goCommand dependencies pinned
Info: 0 out of 4 pipCommand dependencies pinned
Info: 0 out of 3 npmCommand dependencies pinned
Info: 0 out of 2 downloadThenRun dependencies pinned