Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-and-push-images.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/build-and-push-images.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-push-images.yaml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/build-and-push-images.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-and-push-images.yaml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/build-and-push-images.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github-stale.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/github-stale.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-e2e.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-e2e.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-e2e.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-e2e.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-e2e.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-e2e.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-e2e.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-e2e.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-go.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yaml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yaml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-go.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-go.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-python.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-python.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-python.yaml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-python.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-python.yaml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/kubeflow/trainer/test-python.yaml/master?enable=pin
Warn: containerImage not pinned by hash: cmd/initializers/dataset/Dockerfile:1: pin your Docker image by updating python:3.11-alpine to python:3.11-alpine@sha256:32ac7ba3dad4bcee9c8cfaf3b489f832b84ba0a1eb8ef76685456d424baaf444
Warn: containerImage not pinned by hash: cmd/initializers/model/Dockerfile:1: pin your Docker image by updating python:3.11-alpine to python:3.11-alpine@sha256:32ac7ba3dad4bcee9c8cfaf3b489f832b84ba0a1eb8ef76685456d424baaf444
Warn: containerImage not pinned by hash: cmd/runtimes/deepspeed/Dockerfile:1
Warn: containerImage not pinned by hash: cmd/runtimes/deepspeed/Dockerfile:2: pin your Docker image by updating nvidia/cuda:12.4.1-devel-ubuntu22.04 to nvidia/cuda:12.4.1-devel-ubuntu22.04@sha256:da6791294b0b04d7e65d87b7451d6f2390b4d36225ab0701ee7dfec5769829f5
Warn: containerImage not pinned by hash: cmd/runtimes/mlx/Dockerfile:1
Warn: containerImage not pinned by hash: cmd/runtimes/mlx/Dockerfile:2: pin your Docker image by updating debian:trixie to debian:trixie@sha256:653dfb9f86c3782e8369d5f7d29bb8faba1f4bff9025db46e807fa4c22903671
Warn: containerImage not pinned by hash: cmd/trainer-controller-manager/Dockerfile:2
Warn: containerImage not pinned by hash: cmd/trainer-controller-manager/Dockerfile:17: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: containerImage not pinned by hash: cmd/trainers/torchtune/Dockerfile:1: pin your Docker image by updating pytorch/pytorch:2.5.0-cuda12.4-cudnn9-runtime to pytorch/pytorch:2.5.0-cuda12.4-cudnn9-runtime@sha256:f785805521b2f224f5b6ce422a3e6f9cd581aca06599885f45902a7ea45791f6
Warn: pipCommand not pinned by hash: cmd/initializers/dataset/Dockerfile:10
Warn: pipCommand not pinned by hash: cmd/initializers/model/Dockerfile:10
Warn: pipCommand not pinned by hash: cmd/runtimes/deepspeed/Dockerfile:35
Warn: pipCommand not pinned by hash: cmd/runtimes/mlx/Dockerfile:27
Warn: pipCommand not pinned by hash: cmd/runtimes/mlx/Dockerfile:30
Warn: pipCommand not pinned by hash: cmd/trainers/torchtune/Dockerfile:9
Warn: pipCommand not pinned by hash: .github/workflows/test-e2e.yaml:42
Warn: pipCommand not pinned by hash: .github/workflows/test-e2e.yaml:45
Info: 0 out of 14 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 5 third-party GitHubAction dependencies pinned
Info: 0 out of 8 pipCommand dependencies pinned
Info: 0 out of 9 containerImage dependencies pinned