Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:330: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:337: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:345: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:356: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:383: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:386: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:389: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:404: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:428: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:431: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:434: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:442: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:454: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:460: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:197: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:232: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:248: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:277: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:280: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:311: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:486: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:500: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:516: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:519: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:170: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-release.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/docs-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-release.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/docs-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-release.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/docs-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-upstream.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/docs-upstream.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-upstream.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/docs-upstream.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-upstream.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/docs-upstream.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:217: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:220: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:230: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:244: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:250: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labeler.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/labeler.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/validate.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/validate.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/validate.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/validate.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/validate.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/docker/buildx/validate.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:17
Warn: containerImage not pinned by hash: Dockerfile:18
Warn: containerImage not pinned by hash: Dockerfile:19
Warn: containerImage not pinned by hash: Dockerfile:20
Warn: containerImage not pinned by hash: Dockerfile:21
Warn: containerImage not pinned by hash: Dockerfile:22
Warn: containerImage not pinned by hash: Dockerfile:23
Warn: containerImage not pinned by hash: Dockerfile:24
Warn: containerImage not pinned by hash: Dockerfile:25
Warn: containerImage not pinned by hash: Dockerfile:26
Warn: containerImage not pinned by hash: Dockerfile:27
Warn: containerImage not pinned by hash: Dockerfile:29
Warn: containerImage not pinned by hash: Dockerfile:36
Warn: containerImage not pinned by hash: Dockerfile:69
Warn: containerImage not pinned by hash: Dockerfile:77
Warn: containerImage not pinned by hash: Dockerfile:91
Warn: containerImage not pinned by hash: Dockerfile:105
Warn: containerImage not pinned by hash: Dockerfile:106
Warn: containerImage not pinned by hash: Dockerfile:107
Warn: containerImage not pinned by hash: Dockerfile:108
Warn: containerImage not pinned by hash: Dockerfile:109
Warn: containerImage not pinned by hash: Dockerfile:114
Warn: containerImage not pinned by hash: Dockerfile:118
Warn: containerImage not pinned by hash: Dockerfile:144
Warn: containerImage not pinned by hash: Dockerfile:148
Warn: containerImage not pinned by hash: Dockerfile:162
Warn: containerImage not pinned by hash: Dockerfile:163
Warn: containerImage not pinned by hash: Dockerfile:175
Warn: containerImage not pinned by hash: hack/demo-env/examples/compose/Dockerfile:1: pin your Docker image by updating alpine:3.8 to alpine:3.8@sha256:2bb501e6173d9d006e56de5bce2720eb06396803300fe1687b58a7ff32bf4c14
Warn: containerImage not pinned by hash: hack/demo-env/examples/compose/Dockerfile.webapp:1: pin your Docker image by updating alpine:3.8 to alpine:3.8@sha256:2bb501e6173d9d006e56de5bce2720eb06396803300fe1687b58a7ff32bf4c14
Warn: containerImage not pinned by hash: hack/demo-env/examples/simple1/Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: hack/dockerfiles/authors.Dockerfile:5
Warn: containerImage not pinned by hash: hack/dockerfiles/authors.Dockerfile:24
Warn: containerImage not pinned by hash: hack/dockerfiles/docs.Dockerfile:8
Warn: containerImage not pinned by hash: hack/dockerfiles/docs.Dockerfile:14
Warn: containerImage not pinned by hash: hack/dockerfiles/docs.Dockerfile:33
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:13
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:16
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:27
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:37
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:40
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:51
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:58
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:72
Warn: containerImage not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:84
Warn: containerImage not pinned by hash: hack/dockerfiles/govulncheck.Dockerfile:9
Warn: containerImage not pinned by hash: hack/dockerfiles/govulncheck.Dockerfile:17
Warn: containerImage not pinned by hash: hack/dockerfiles/lint.Dockerfile:13
Warn: containerImage not pinned by hash: hack/dockerfiles/lint.Dockerfile:15
Warn: containerImage not pinned by hash: hack/dockerfiles/lint.Dockerfile:18
Warn: containerImage not pinned by hash: hack/dockerfiles/lint.Dockerfile:26
Warn: containerImage not pinned by hash: hack/dockerfiles/lint.Dockerfile:32
Warn: containerImage not pinned by hash: hack/dockerfiles/lint.Dockerfile:36
Warn: containerImage not pinned by hash: hack/dockerfiles/lint.Dockerfile:64
Warn: containerImage not pinned by hash: hack/dockerfiles/lint.Dockerfile:80
Warn: containerImage not pinned by hash: hack/dockerfiles/vendor.Dockerfile:8
Warn: containerImage not pinned by hash: hack/dockerfiles/vendor.Dockerfile:12
Warn: containerImage not pinned by hash: hack/dockerfiles/vendor.Dockerfile:27
Warn: containerImage not pinned by hash: hack/dockerfiles/vendor.Dockerfile:42
Warn: containerImage not pinned by hash: hack/dockerfiles/vendor.Dockerfile:43
Warn: goCommand not pinned by hash: Dockerfile:42-48
Warn: goCommand not pinned by hash: hack/dockerfiles/generated-files.Dockerfile:59-66
Warn: downloadThenRun not pinned by hash: hack/dockerfiles/lint.Dockerfile:21
Warn: goCommand not pinned by hash: vendor/github.com/agext/levenshtein/test.sh:5
Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10
Warn: goCommand not pinned by hash: vendor/github.com/pelletier/go-toml/benchmark.sh:10
Info: 0 out of 30 GitHub-owned GitHubAction dependencies pinned
Info: 7 out of 36 third-party GitHubAction dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 0 out of 60 containerImage dependencies pinned
Info: 0 out of 5 goCommand dependencies pinned