Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/jan--f/prometheus-operator/ci.yaml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:3
Warn: containerImage not pinned by hash: cmd/prometheus-config-reloader/Dockerfile:3
Warn: containerImage not pinned by hash: example/alertmanger-webhook/Dockerfile:1: pin your Docker image by updating quay.io/prometheus/busybox:latest to quay.io/prometheus/busybox:latest@sha256:dfa54ef35e438b9e71ac5549159074576b6382f95ce1a434088e05fd6b730bc4
Warn: containerImage not pinned by hash: scripts/tooling/Dockerfile:1
Warn: containerImage not pinned by hash: scripts/tooling/Dockerfile:31: pin your Docker image by updating golang:1.14 to golang:1.14@sha256:1a7173b5b9a3af3e29a5837e0b2027e1c438fd1b83bbee8f221355087ad416d6
Warn: containerImage not pinned by hash: test/instrumented-sample-app/Dockerfile:1
Warn: containerImage not pinned by hash: test/instrumented-sample-app/Dockerfile:6: pin your Docker image by updating alpine:3.7 to alpine:3.7@sha256:8421d9a84432575381bfabd248f1eb56f3aa21d9d7cd2511583c68c9b7511d10
Warn: goCommand not pinned by hash: scripts/tooling/Dockerfile:22
Warn: goCommand not pinned by hash: scripts/tooling/Dockerfile:23
Info: 0 out of 17 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 4 third-party GitHubAction dependencies pinned
Info: 0 out of 7 containerImage dependencies pinned
Info: 0 out of 2 goCommand dependencies pinned