Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_base_image.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_base_image.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_base_image.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_base_image.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_base_image.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_base_image.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_base_image.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_base_image.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_base_image.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_base_image.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_base_image.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_base_image.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_base_image.yaml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_base_image.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:123: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:127: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:165: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:172: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:226: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:238: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:293: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:302: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:305: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:306: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:311: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:324: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:336: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:345: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:363: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:364: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:369: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:379: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:407: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build_packages.yaml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/build_packages.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check_markdown.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/check_markdown.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check_markdown.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/check_markdown.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/commit_message.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/commit_message.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/commit_message.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/commit_message.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/commit_message.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/commit_message.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy_docs.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/deploy_docs.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy_docs.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/deploy_docs.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy_docs.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/deploy_docs.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy_docs.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/deploy_docs.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy_docs.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/deploy_docs.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy_docs.yaml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/deploy_docs.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy_docs.yaml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/deploy_docs.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/lint.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/lint.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/lint.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/lint.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/lint.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yaml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/lint.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/lint.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:160: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:189: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:211: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:216: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:244: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:256: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:257: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_fvt_tests.yaml:265: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_fvt_tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/run_test_case.yaml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/run_test_case.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/upload_sdk.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/upload_sdk.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/upload_sdk.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/lf-edge/ekuiper/upload_sdk.yaml/master?enable=pin
Warn: containerImage not pinned by hash: .github/dockerfile/Dockerfile.alpine:16
Warn: containerImage not pinned by hash: .github/dockerfile/Dockerfile.debian:16: pin your Docker image by updating debian:bullseye to debian:bullseye@sha256:2a7f95bcf104c8410bf4d3b13c52f6e0e4334bb2edf8d80c7f9881e49447effe
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile:16
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile:24: pin your Docker image by updating alpine:3.20.0 to alpine:3.20.0@sha256:77726ef6b57ddf65bb551896826ec38bc3e53f75cdde31354fbffb4f25238ebd
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-alpine-python:16
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-alpine-python:24: pin your Docker image by updating python:3.12-alpine to python:3.12-alpine@sha256:c08bfdbffc9184cdfd225497bac12b2c0dac1d24bbe13287cfb7d99f1116cf43
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-dev:16
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-full:16
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-full:24: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:4b50eb66f977b4062683ff434ef18ac191da862dbe966961bc11990cf5791a8d
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-kubernetes-tool:15
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-kubernetes-tool:23: pin your Docker image by updating alpine:3.20.0 to alpine:3.20.0@sha256:77726ef6b57ddf65bb551896826ec38bc3e53f75cdde31354fbffb4f25238ebd
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-slim:16
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-slim:24: pin your Docker image by updating debian:bookworm-slim to debian:bookworm-slim@sha256:4b50eb66f977b4062683ff434ef18ac191da862dbe966961bc11990cf5791a8d
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-slim-python:16
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-slim-python:24
Warn: containerImage not pinned by hash: deploy/docker/Dockerfile-slim-python:43: pin your Docker image by updating python:3.12-slim-bookworm to python:3.12-slim-bookworm@sha256:bae1a061b657f403aaacb1069a7f67d91f7ef5725ab17ca36abc5f1b2797ff92
Warn: pipCommand not pinned by hash: deploy/docker/Dockerfile-slim-python:31-38
Warn: npmCommand not pinned by hash: .github/workflows/check_markdown.yaml:17
Warn: goCommand not pinned by hash: .github/workflows/lint.yaml:30
Warn: pipCommand not pinned by hash: .github/workflows/run_fvt_tests.yaml:53
Warn: pipCommand not pinned by hash: .github/workflows/run_fvt_tests.yaml:54
Warn: downloadThenRun not pinned by hash: .github/workflows/run_fvt_tests.yaml:309
Warn: pipCommand not pinned by hash: .github/workflows/run_test_case.yaml:35
Warn: pipCommand not pinned by hash: .github/workflows/upload_sdk.yaml:23
Warn: pipCommand not pinned by hash: .github/workflows/upload_sdk.yaml:40
Warn: pipCommand not pinned by hash: .github/workflows/upload_sdk.yaml:62
Info: 0 out of 54 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 30 third-party GitHubAction dependencies pinned
Info: 0 out of 16 containerImage dependencies pinned
Info: 0 out of 7 pipCommand dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned