Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/swagger-change-notification.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/swagger-change-notification.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/swagger-change-notification.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/swagger-change-notification.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-nightly.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/test-nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-nightly.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/test-nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-nightly.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/test-nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-nightly.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/test-nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verifyPR.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/verifyPR.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/verifyPR.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/konveyor/tackle2-hub/verifyPR.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:3
Warn: containerImage not pinned by hash: Dockerfile:14
Warn: containerImage not pinned by hash: Dockerfile:16: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal to registry.access.redhat.com/ubi9/ubi-minimal@sha256:e1c4703364c5cb58f5462575dc90345bcd934ddc45e6c32f9c162f2b5617681c
Warn: containerImage not pinned by hash: hack/cmd/addon/Dockerfile:1
Warn: containerImage not pinned by hash: hack/cmd/addon/Dockerfile:6: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal:8.4 to registry.access.redhat.com/ubi8/ubi-minimal:8.4@sha256:c536d4c63253318fdfc1db499f8f4bb0881db7fbd6f3d1554b4d54c812f85cc7
Info: 0 out of 18 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 2 third-party GitHubAction dependencies pinned
Info: 0 out of 5 containerImage dependencies pinned