Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/after-push-to-branch.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/after-push-to-branch.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/after-push-to-branch.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/after-push-to-branch.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/after-tag-with-version.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/after-tag-with-version.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/after-tag-with-version.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/after-tag-with-version.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-doc-sync.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/check-doc-sync.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/firebase-hosting-merge.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/firebase-hosting-merge.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/firebase-hosting-merge.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/firebase-hosting-merge.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/release.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-docs.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/verify-docs.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-docs.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/verify-docs.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-docs.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/GoogleContainerTools/kpt-functions-catalog/verify-docs.yaml/master?enable=pin
Warn: containerImage not pinned by hash: build/docker/go/Dockerfile:5
Warn: containerImage not pinned by hash: build/docker/go/Dockerfile:18
Warn: containerImage not pinned by hash: build/docker/ts/Dockerfile:5
Warn: containerImage not pinned by hash: build/docker/ts/Dockerfile:27
Warn: containerImage not pinned by hash: contrib/functions/ts/analyze-istio/build/analyze_istio.Dockerfile:5
Warn: containerImage not pinned by hash: contrib/functions/ts/analyze-istio/build/analyze_istio.Dockerfile:35
Warn: containerImage not pinned by hash: contrib/functions/ts/sops/build/sops.Dockerfile:5
Warn: containerImage not pinned by hash: contrib/functions/ts/sops/build/sops.Dockerfile:39
Warn: containerImage not pinned by hash: functions/go/render-helm-chart/Dockerfile:5
Warn: containerImage not pinned by hash: functions/go/render-helm-chart/Dockerfile:24
Warn: containerImage not pinned by hash: functions/ts/kubeval/build/kubeval.Dockerfile:4
Warn: containerImage not pinned by hash: functions/ts/kubeval/build/kubeval.Dockerfile:26
Warn: containerImage not pinned by hash: functions/ts/kubeval/build/kubeval.Dockerfile:35
Warn: containerImage not pinned by hash: hack/Dockerfile:19: pin your Docker image by updating docker to docker@sha256:f49e1c71b5d9f8ebe53715f78996ce42b8be4b1ec03875d187dfe3c03de1dc00
Warn: containerImage not pinned by hash: site/Dockerfile:2: pin your Docker image by updating nginx:1.18.0-alpine to nginx:1.18.0-alpine@sha256:93baf2ec1bfefd04d29eb070900dd5d79b0f79863653453397e55a5b663a6cb1
Warn: npmCommand not pinned by hash: scripts/check-site.sh:19
Warn: npmCommand not pinned by hash: scripts/version-kpt-functions-sdk-deps.sh:26
Warn: goCommand not pinned by hash: .github/workflows/ci.yaml:101
Warn: pipCommand not pinned by hash: .github/workflows/verify-docs.yaml:21
Info: 0 out of 19 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 1 third-party GitHubAction dependencies pinned
Info: 2 out of 3 goCommand dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 15 containerImage dependencies pinned
Info: 4 out of 6 npmCommand dependencies pinned