Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checkDocSync.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/checkDocSync.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checkLicenses.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/checkLicenses.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checkLicenses.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/checkLicenses.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checkLicenses.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/checkLicenses.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checkSite.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/checkSite.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checkSite.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/checkSite.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2eEnvironment.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/e2eEnvironment.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2eEnvironment.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/e2eEnvironment.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/firebase-hosting-merge.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/firebase-hosting-merge.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/firebase-hosting-merge.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/firebase-hosting-merge.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/go.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/live-e2e.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/live-e2e.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/live-e2e.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/live-e2e.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verifyContent.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/verifyContent.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verifyContent.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/kptdev/kpt/verifyContent.yml/main?enable=pin
Warn: containerImage not pinned by hash: release/images/Dockerfile:15: pin your Docker image by updating alpine:3.18 to alpine:3.18@sha256:de0eb0b3f2a47ba1eb89389859a9bd88b28e82f5826b6969ad604979713c2d4f
Warn: containerImage not pinned by hash: release/images/Dockerfile-gcloud:15: pin your Docker image by updating gcr.io/google.com/cloudsdktool/cloud-sdk:367.0.0-alpine to gcr.io/google.com/cloudsdktool/cloud-sdk:367.0.0-alpine@sha256:a93e1b1360565749bdf2c84bdb6d6e2c8efd146fd679e367d1e9934c33122c03
Warn: containerImage not pinned by hash: rollouts/Dockerfile:16
Warn: containerImage not pinned by hash: rollouts/Dockerfile:43: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:6ec5aa99dc335666e79dc64e4a6c8b89c33a543a1967f20d360922a80dd21f02
Warn: containerImage not pinned by hash: site/Dockerfile:1: pin your Docker image by updating nginx:1.18.0-alpine to nginx:1.18.0-alpine@sha256:93baf2ec1bfefd04d29eb070900dd5d79b0f79863653453397e55a5b663a6cb1
Warn: npmCommand not pinned by hash: scripts/check-site.sh:20
Warn: npmCommand not pinned by hash: scripts/generate-sitemap.sh:20
Warn: npmCommand not pinned by hash: .github/workflows/checkSite.yml:40
Info: 0 out of 20 GitHub-owned GitHubAction dependencies pinned
Info: 3 out of 5 third-party GitHubAction dependencies pinned
Info: 0 out of 5 containerImage dependencies pinned
Info: 0 out of 3 npmCommand dependencies pinned