Info: Possibly incomplete results: error parsing shell code: not a valid arithmetic operator: describe: tools/image-tag:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/backport.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/backport.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/backport.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/backport.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/conventional-commits.yml:8: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/conventional-commits.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dependabot_reviewer.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/dependabot_reviewer.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/dependabot_reviewer.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/dependabot_reviewer.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-ci.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-ci.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-ci.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-ci.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-ci.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-diff-ci.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-diff-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-diff-ci.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-diff-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-diff-ci.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-diff-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-diff-ci.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-diff-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-diff-ci.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-diff-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-diff-ci.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-diff-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-tagged-release-pr.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-tagged-release-pr.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-tagged-release-pr.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-tagged-release-pr.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-tagged-release-pr.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-tagged-release-pr.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-tagged-release-pr.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-tagged-release-pr.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-weekly-release-pr.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-weekly-release-pr.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-weekly-release-pr.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-weekly-release-pr.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-weekly-release-pr.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-weekly-release-pr.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-weekly-release-pr.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-weekly-release-pr.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-weekly-release-pr.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-weekly-release-pr.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-weekly-release-pr.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/helm-weekly-release-pr.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:127: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:298: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:300: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:332: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:338: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:343: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:347: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:349: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:368: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:514: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:516: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:190: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:192: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:224: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:230: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:235: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:239: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:241: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:406: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:408: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:440: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:446: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/images.yml:451: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:455: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:457: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/images.yml:476: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labeler.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/labeler.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint-jsonnet.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/lint-jsonnet.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint-jsonnet.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/lint-jsonnet.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/logql-analyzer.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/logql-analyzer.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/logql-analyzer.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/logql-analyzer.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/logql-analyzer.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/logql-analyzer.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/logql-analyzer.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/logql-analyzer.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/logql-analyzer.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/logql-analyzer.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/logql-analyzer.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/logql-analyzer.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/logql-analyzer.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/logql-analyzer.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/metrics-collector.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/metrics-collector.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:361: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:367: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:372: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:376: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:380: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:395: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:405: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:559: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:565: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:570: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:574: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:578: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:593: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:603: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:708: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:714: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:719: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:723: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:727: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:742: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:752: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:841: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:847: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:852: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:863: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:188: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:203: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:231: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:237: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:242: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:246: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:250: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:265: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:275: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:293: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:299: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:304: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:308: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:312: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:327: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:337: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:423: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:429: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:434: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:438: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:442: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:457: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:467: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:491: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:497: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:502: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:506: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:510: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:525: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:535: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:627: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:633: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:638: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:642: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:646: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:648: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:667: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:687: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:776: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:782: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:787: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:791: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:795: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:810: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:820: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minor-release-pr.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/minor-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nix-ci.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/nix-ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nix-ci.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/nix-ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nix-ci.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/nix-ci.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nix-ci.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/nix-ci.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-bundle.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-bundle.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-bundle.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-bundle.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-check-prepare-release-commit.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-check-prepare-release-commit.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-check-prepare-release-commit.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-check-prepare-release-commit.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-images.yaml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-images.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-release-please.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-release-please.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-release-please.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-release-please.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-release-please.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-release-please.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-release-please.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-release-please.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-release-please.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-release-please.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-release-please.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-release-please.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-release-please.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-release-please.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-release-please.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-release-please.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-reusable-hub-release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-reusable-hub-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-reusable-hub-release.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-reusable-hub-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-reusable-hub-release.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-reusable-hub-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-reusable-hub-release.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-reusable-hub-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-scorecard.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-scorecard.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-scorecard.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-scorecard.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-scorecard.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator-scorecard.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator.yaml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/operator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:627: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:633: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:638: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:642: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:646: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:648: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:667: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:687: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:708: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:714: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:719: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:723: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:727: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:742: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:752: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:231: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:237: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:242: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:246: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:250: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:265: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:275: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:361: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:367: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:372: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:376: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:380: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:395: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:405: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:491: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:497: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:502: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:506: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:510: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:525: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:535: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:776: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:782: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:787: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:791: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:795: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:810: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:820: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:841: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:847: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:852: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:863: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:188: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:203: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:293: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:299: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:304: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:308: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:312: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:327: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:337: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:423: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:429: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:434: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:438: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:442: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:457: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:467: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:559: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:565: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:570: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:574: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:578: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:593: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/patch-release-pr.yml:603: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/patch-release-pr.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/promtail-windows-test.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/promtail-windows-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/promtail-windows-test.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/promtail-windows-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-technical-documentation-next.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/publish-technical-documentation-next.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-technical-documentation-next.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/publish-technical-documentation-next.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-technical-documentation-release.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/publish-technical-documentation-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-technical-documentation-release.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/publish-technical-documentation-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:211: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:215: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:219: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:221: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:223: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:243: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:249: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:253: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:257: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:259: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:261: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:282: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:289: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:320: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:325: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/secret-scanning.yml:8: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/secret-scanning.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/secret-scanning.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/secret-scanning.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/syft-sbom-ci.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/syft-sbom-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/syft-sbom-ci.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/syft-sbom-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-release-workflow.yaml:7: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/verify-release-workflow.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-release-workflow.yaml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/grafana/loki/verify-release-workflow.yaml/main?enable=pin
Warn: containerImage not pinned by hash: clients/cmd/docker-driver/Dockerfile:7
Warn: containerImage not pinned by hash: clients/cmd/docker-driver/Dockerfile:14
Warn: containerImage not pinned by hash: clients/cmd/docker-driver/Dockerfile:20: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: clients/cmd/fluent-bit/Dockerfile:1
Warn: containerImage not pinned by hash: clients/cmd/fluentd/Dockerfile:1
Warn: containerImage not pinned by hash: clients/cmd/fluentd/Dockerfile:12: pin your Docker image by updating fluent/fluentd:v1.18-debian-1 to fluent/fluentd:v1.18-debian-1@sha256:595aedef40388e8eaeca51c830db7290d0d4232947907d38c774e7901eb2a01e
Warn: containerImage not pinned by hash: clients/cmd/logstash/Dockerfile:1: pin your Docker image by updating logstash:8.17.4 to logstash:8.17.4@sha256:22b4c2aad529320d4faafb6927dc39f62d6bcf6cfa92085e0fe67cae8ec3a036
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile:3
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile:12: pin your Docker image by updating public.ecr.aws/ubuntu/ubuntu:noble to public.ecr.aws/ubuntu/ubuntu:noble@sha256:4d860156ddae5923ed93d6b161c6b2f0f437d8086210f087db85b83fc2689914
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile.arm32:1
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile.arm32:9: pin your Docker image by updating public.ecr.aws/ubuntu/ubuntu:noble to public.ecr.aws/ubuntu/ubuntu:noble@sha256:4d860156ddae5923ed93d6b161c6b2f0f437d8086210f087db85b83fc2689914
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile.cross:6
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile.cross:10
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile.cross:17: pin your Docker image by updating public.ecr.aws/ubuntu/ubuntu:noble to public.ecr.aws/ubuntu/ubuntu:noble@sha256:4d860156ddae5923ed93d6b161c6b2f0f437d8086210f087db85b83fc2689914
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile.debug:5
Warn: containerImage not pinned by hash: clients/cmd/promtail/Dockerfile.debug:12: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: cmd/logcli/Dockerfile:3
Warn: containerImage not pinned by hash: cmd/logcli/Dockerfile:10: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: cmd/logql-analyzer/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/logql-analyzer/Dockerfile:8: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: cmd/loki-canary-boringcrypto/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/loki-canary-boringcrypto/Dockerfile:10: pin your Docker image by updating gcr.io/distroless/base-nossl:debug to gcr.io/distroless/base-nossl:debug@sha256:bb4f0846ad2311d467bfc855b9d231eb665089ce9ccc6aca04bed25ab047ab74
Warn: containerImage not pinned by hash: cmd/loki-canary/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/loki-canary/Dockerfile:9: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: cmd/loki-canary/Dockerfile.cross:6
Warn: containerImage not pinned by hash: cmd/loki-canary/Dockerfile.cross:10
Warn: containerImage not pinned by hash: cmd/loki-canary/Dockerfile.cross:16: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: cmd/loki/Dockerfile:4
Warn: containerImage not pinned by hash: cmd/loki/Dockerfile:11
Warn: containerImage not pinned by hash: cmd/loki/Dockerfile:19: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: cmd/loki/Dockerfile.cross:5
Warn: containerImage not pinned by hash: cmd/loki/Dockerfile.cross:13: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: cmd/loki/Dockerfile.debug:7
Warn: containerImage not pinned by hash: cmd/loki/Dockerfile.debug:12
Warn: containerImage not pinned by hash: cmd/loki/Dockerfile.debug:19: pin your Docker image by updating gcr.io/distroless/base-nossl:debug to gcr.io/distroless/base-nossl:debug@sha256:bb4f0846ad2311d467bfc855b9d231eb665089ce9ccc6aca04bed25ab047ab74
Warn: containerImage not pinned by hash: cmd/migrate/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/migrate/Dockerfile:7: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: cmd/querytee/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/querytee/Dockerfile:9: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: cmd/querytee/Dockerfile.cross:6
Warn: containerImage not pinned by hash: cmd/querytee/Dockerfile.cross:10
Warn: containerImage not pinned by hash: cmd/querytee/Dockerfile.cross:16: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:11
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:20
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:29
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:34
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:40
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:43
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:53
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:57
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:62
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:66
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:70
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:74
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:79
Warn: containerImage not pinned by hash: loki-build-image/Dockerfile:81
Warn: containerImage not pinned by hash: operator/Dockerfile:2
Warn: containerImage not pinned by hash: operator/Dockerfile:22: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: containerImage not pinned by hash: operator/Dockerfile.cross:3
Warn: containerImage not pinned by hash: operator/Dockerfile.cross:7
Warn: containerImage not pinned by hash: operator/Dockerfile.cross:27: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: containerImage not pinned by hash: operator/calculator.Dockerfile:2
Warn: containerImage not pinned by hash: operator/calculator.Dockerfile:22: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: containerImage not pinned by hash: production/helm/loki/src/helm-test/Dockerfile:2
Warn: containerImage not pinned by hash: production/helm/loki/src/helm-test/Dockerfile:11: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:5c474275684bbf271ec40502ab50158b2f9826de5877d8feec27e22e8d6ee3d2
Warn: containerImage not pinned by hash: tools/bigtable-backup/Dockerfile:1: pin your Docker image by updating grafana/bigtable-backup:master-18e7589 to grafana/bigtable-backup:master-18e7589@sha256:7ad47b8cfcf48bb9a56903745d56fa22c2ee0a0f8005b1a6d50fe4da036dda5d
Warn: containerImage not pinned by hash: tools/dev/loki-tsdb-storage-s3/dev.dockerfile:1: pin your Docker image by updating golang:1.23 to golang:1.23@sha256:a5339982f2e78b38b26ebbee35139854e184a4e90e1516f9f636371e720b727b
Warn: containerImage not pinned by hash: tools/dev/loki-tsdb-storage-s3/dev.dockerfile:5: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: tools/lambda-promtail/Dockerfile:1
Warn: containerImage not pinned by hash: tools/lambda-promtail/Dockerfile:16: pin your Docker image by updating public.ecr.aws/lambda/provided:al2 to public.ecr.aws/lambda/provided:al2@sha256:9887710f0cb874b56f725e823beda9d6c90b50199e97c81123910e704241ee64
Warn: goCommand not pinned by hash: cmd/loki/Dockerfile.debug:8-10
Warn: downloadThenRun not pinned by hash: loki-build-image/Dockerfile:30-32
Warn: goCommand not pinned by hash: loki-build-image/Dockerfile:58
Warn: goCommand not pinned by hash: loki-build-image/Dockerfile:63
Warn: goCommand not pinned by hash: loki-build-image/Dockerfile:129
Warn: pipCommand not pinned by hash: tools/bigtable-backup/Dockerfile:2-3
Warn: pipCommand not pinned by hash: tools/bigtable-backup/Dockerfile:6
Warn: goCommand not pinned by hash: .github/vendor/github.com/grafana/loki-release/workflows/install_workflow_dependencies.sh:51
Warn: goCommand not pinned by hash: vendor/cloud.google.com/go/bigtable/conformance_test.sh:54
Warn: pipCommand not pinned by hash: vendor/github.com/gocql/gocql/install_test_deps.sh:6
Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10
Warn: npmCommand not pinned by hash: .github/workflows/backport.yml:21
Warn: npmCommand not pinned by hash: .github/workflows/metrics-collector.yml:19
Warn: npmCommand not pinned by hash: .github/workflows/minor-release-pr.yml:879
Warn: npmCommand not pinned by hash: .github/workflows/minor-release-pr.yml:80
Warn: npmCommand not pinned by hash: .github/workflows/patch-release-pr.yml:879
Warn: npmCommand not pinned by hash: .github/workflows/patch-release-pr.yml:80
Warn: npmCommand not pinned by hash: .github/workflows/release.yml:89
Info: 0 out of 160 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 173 third-party GitHubAction dependencies pinned
Info: 1 out of 71 containerImage dependencies pinned
Info: 21 out of 28 goCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 0 out of 3 pipCommand dependencies pinned
Info: 0 out of 7 npmCommand dependencies pinned