Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-and-push-images.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/build-and-push-images.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-push-images.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/build-and-push-images.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github-stale.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/github-stale.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/github-trigger-rerun-test.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/github-trigger-rerun-test.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-e2e.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-e2e.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-e2e.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-e2e.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yaml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-go.yaml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-python.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-python.yaml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-python.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-python.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-python.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: containerImage not pinned by hash: cmd/initializer/dataset/Dockerfile:1: pin your Docker image by updating python:3.11-alpine to python:3.11-alpine@sha256:d5e2fc72296647869f5eeb09e7741088a1841195059de842b05b94cb9d3771bb
Warn: containerImage not pinned by hash: cmd/initializer/model/Dockerfile:1: pin your Docker image by updating python:3.11-alpine to python:3.11-alpine@sha256:d5e2fc72296647869f5eeb09e7741088a1841195059de842b05b94cb9d3771bb
Warn: containerImage not pinned by hash: cmd/trainer-controller-manager/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/trainer-controller-manager/Dockerfile:17: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:6ec5aa99dc335666e79dc64e4a6c8b89c33a543a1967f20d360922a80dd21f02
Warn: pipCommand not pinned by hash: cmd/initializer/dataset/Dockerfile:10
Warn: pipCommand not pinned by hash: cmd/initializer/dataset/Dockerfile:19
Warn: pipCommand not pinned by hash: cmd/initializer/model/Dockerfile:10
Warn: pipCommand not pinned by hash: cmd/initializer/model/Dockerfile:19
Info: 0 out of 12 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 4 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 0 out of 4 pipCommand dependencies pinned