Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/close-stale-issues.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/close-stale-issues.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-health.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/code-health.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-health.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/code-health.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/code-health.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/code-health.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-health.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/code-health.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/code-health.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/code-health.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/comment-release-pr.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/comment-release-pr.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-dispatch.yml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-dispatch.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:162: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:187: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:191: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-fork.yml:236: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e-fork.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:191: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:195: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yml:240: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/kubelinter-check.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/kubelinter-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/kubelinter-check.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/kubelinter-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/kubelinter-check.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/kubelinter-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/kubelinter-check.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/kubelinter-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/kubelinter-check.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/kubelinter-check.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/main.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-images.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-images.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-images.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-images.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-images.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-images.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-images.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-images.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-images.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-images.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-images.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-images.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-images.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-images.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-single-image.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-single-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-single-image.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-single-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-single-image.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-single-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-single-image.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-single-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-single-image.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/release-single-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/remove-label.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/mongodb/mongodb-kubernetes-operator/remove-label.yml/master?enable=pin
Warn: containerImage not pinned by hash: scripts/dev/templates/operator/Dockerfile.builder:2
Warn: containerImage not pinned by hash: scripts/dev/templates/operator/Dockerfile.builder:13: pin your Docker image by updating busybox to busybox@sha256:37f7b378a29ceb4c551b1b5582e27747b855bbfaa73fa11914fe0df028dc581f
Warn: containerImage not pinned by hash: scripts/dev/templates/operator/Dockerfile.operator:2
Warn: containerImage not pinned by hash: scripts/dev/templates/operator/Dockerfile.operator:4
Warn: containerImage not pinned by hash: scripts/dev/templates/readiness/Dockerfile.builder:2
Warn: containerImage not pinned by hash: scripts/dev/templates/readiness/Dockerfile.builder:13: pin your Docker image by updating busybox to busybox@sha256:37f7b378a29ceb4c551b1b5582e27747b855bbfaa73fa11914fe0df028dc581f
Warn: containerImage not pinned by hash: scripts/dev/templates/readiness/Dockerfile.readiness:2
Warn: containerImage not pinned by hash: scripts/dev/templates/readiness/Dockerfile.readiness:4
Warn: containerImage not pinned by hash: scripts/dev/templates/versionhook/Dockerfile.builder:2
Warn: containerImage not pinned by hash: scripts/dev/templates/versionhook/Dockerfile.builder:13: pin your Docker image by updating busybox to busybox@sha256:37f7b378a29ceb4c551b1b5582e27747b855bbfaa73fa11914fe0df028dc581f
Warn: containerImage not pinned by hash: scripts/dev/templates/versionhook/Dockerfile.versionhook:2
Warn: containerImage not pinned by hash: scripts/dev/templates/versionhook/Dockerfile.versionhook:4
Warn: containerImage not pinned by hash: test/test-app/Dockerfile:1: pin your Docker image by updating python:3.8-slim-buster to python:3.8-slim-buster@sha256:8799b0564103a9f36cfb8a8e1c562e11a9a6f2e3bb214e2adc23982b36a04511
Warn: pipCommand not pinned by hash: test/test-app/Dockerfile:7
Warn: goCommand not pinned by hash: scripts/git-hooks/pre-commit:8
Warn: pipCommand not pinned by hash: .github/workflows/e2e-dispatch.yml:66
Warn: pipCommand not pinned by hash: .github/workflows/e2e-dispatch.yml:105
Warn: pipCommand not pinned by hash: .github/workflows/e2e-fork.yml:68
Warn: pipCommand not pinned by hash: .github/workflows/e2e-fork.yml:197
Warn: pipCommand not pinned by hash: .github/workflows/e2e.yml:201
Warn: pipCommand not pinned by hash: .github/workflows/e2e.yml:74
Warn: pipCommand not pinned by hash: .github/workflows/main.yaml:50
Warn: pipCommand not pinned by hash: .github/workflows/release-images.yml:38
Warn: pipCommand not pinned by hash: .github/workflows/release-single-image.yml:30
Info: 0 out of 40 GitHub-owned GitHubAction dependencies pinned
Info: 2 out of 23 third-party GitHubAction dependencies pinned
Info: 0 out of 13 containerImage dependencies pinned
Info: 0 out of 10 pipCommand dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned