Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/helm.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/helm.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-ld.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/push-ld.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-ld.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/push-ld.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-ld.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/push-ld.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-ld.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/push-ld.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-ld.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/push-ld.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-ld.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/push-ld.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-ld.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/push-ld.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scan.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/scan.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/scan.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/scan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scan.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/scan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scan.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/scan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scan.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/scan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scan.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/scan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/scan.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/fluxcd/flagger/scan.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:4
Warn: containerImage not pinned by hash: Dockerfile:5
Warn: containerImage not pinned by hash: Dockerfile:32: pin your Docker image by updating alpine:3.21 to alpine:3.21@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: Dockerfile.loadtester:1
Warn: containerImage not pinned by hash: Dockerfile.loadtester:42: pin your Docker image by updating bash:5.2 to bash:5.2@sha256:64defcbc5126c2d81122b4fb78a629a6d27068f0842c4a8302b8273415b12e30
Warn: downloadThenRun not pinned by hash: test/gatewayapi/install.sh:17
Warn: downloadThenRun not pinned by hash: test/istio/install.sh:12
Warn: downloadThenRun not pinned by hash: test/kuma/install.sh:10
Warn: goCommand not pinned by hash: .github/workflows/build.yaml:33
Info: 0 out of 13 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 22 third-party GitHubAction dependencies pinned
Info: 0 out of 5 containerImage dependencies pinned
Info: 0 out of 3 downloadThenRun dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned