Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-enterprise.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/integration-enterprise.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-enterprise.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/integration-enterprise.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/integration-enterprise.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/integration-enterprise.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/integration-enterprise.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/integration-enterprise.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-konnect.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/integration-konnect.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-konnect.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/integration-konnect.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/integration.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/integration.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/test.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/test.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/test.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/validate-kong-release.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/validate-kong-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate-kong-release.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/validate-kong-release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate-kong-release.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/validate-kong-release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/validate-kong-release.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/Kong/deck/validate-kong-release.yaml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:12: pin your Docker image by updating alpine:3.21.2 to alpine:3.21.2@sha256:56fa17d2a7e7f168a043a2712e63aed1f8543aeafdcee47c58dcffe38ed51099
Info: 0 out of 23 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 11 third-party GitHubAction dependencies pinned
Info: 0 out of 2 containerImage dependencies pinned