Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build-dev-images.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build-dev-images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-dev-images.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build-dev-images.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build-dev-images.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build-dev-images.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:143: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:159: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:161: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:189: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:190: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:201: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:202: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:214: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/check-links.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/check-links.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/check-links.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/check-links.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/close-stale.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/close-stale.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:164: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generated-docs.yaml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/generated-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-mod-tidy.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/go-mod-tidy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-mod-tidy.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/go-mod-tidy.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/golangci-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-lint.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/helm-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-lint.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/helm-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/nightly.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/openshift-preflight.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/openshift-preflight.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/openshift-preflight.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/openshift-preflight.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:280: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:292: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:297: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:192: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:195: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:199: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:207: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:214: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-modules.yml:220: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-modules.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-odiglet-base-builder.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/publish-odiglet-base-builder.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:176: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:186: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-artifactregistry.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release-artifactregistry.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync-logos-s3-bucket.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/sync-logos-s3-bucket.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sync-logos-s3-bucket.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/sync-logos-s3-bucket.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tag-patch.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/tag-patch.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-otel-versions.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/update-otel-versions.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-otel-versions.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/update-otel-versions.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-api-crds.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-api-crds.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-api-crds.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-api-crds.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-collector-ocb.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-collector-ocb.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-collector-ocb.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-collector-ocb.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-odiglet-base-builder.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/verify-odiglet-base-builder.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/verify-odiglet-base-builder.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-odiglet-base-builder.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/verify-odiglet-base-builder.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/odigos-io/odigos/verify-odiglet-base-builder.yaml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: Dockerfile:31: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: containerImage not pinned by hash: Dockerfile.rhel:1
Warn: containerImage not pinned by hash: Dockerfile.rhel:30: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:dca8bc186bb579f36414c6ad28f1dbeda33e5cf0bd5fc1c51430cc578e25f819
Warn: containerImage not pinned by hash: collector/Dockerfile:1
Warn: containerImage not pinned by hash: collector/Dockerfile:8: pin your Docker image by updating gcr.io/distroless/base:latest to gcr.io/distroless/base:latest@sha256:27769871031f67460f1545a52dfacead6d18a9f197db77110cfc649ca2a91f44
Warn: containerImage not pinned by hash: collector/Dockerfile.rhel:1
Warn: containerImage not pinned by hash: collector/Dockerfile.rhel:9: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:dca8bc186bb579f36414c6ad28f1dbeda33e5cf0bd5fc1c51430cc578e25f819
Warn: containerImage not pinned by hash: frontend/Dockerfile:1
Warn: containerImage not pinned by hash: frontend/Dockerfile:6
Warn: containerImage not pinned by hash: frontend/Dockerfile:12
Warn: containerImage not pinned by hash: frontend/Dockerfile:21: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: containerImage not pinned by hash: frontend/Dockerfile.rhel:1
Warn: containerImage not pinned by hash: frontend/Dockerfile.rhel:6
Warn: containerImage not pinned by hash: frontend/Dockerfile.rhel:12
Warn: containerImage not pinned by hash: frontend/Dockerfile.rhel:22: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:dca8bc186bb579f36414c6ad28f1dbeda33e5cf0bd5fc1c51430cc578e25f819
Warn: containerImage not pinned by hash: odiglet/Dockerfile:3
Warn: containerImage not pinned by hash: odiglet/Dockerfile:18
Warn: containerImage not pinned by hash: odiglet/Dockerfile:34
Warn: containerImage not pinned by hash: odiglet/Dockerfile:50
Warn: containerImage not pinned by hash: odiglet/Dockerfile:59
Warn: containerImage not pinned by hash: odiglet/Dockerfile:87
Warn: containerImage not pinned by hash: odiglet/Dockerfile:97
Warn: containerImage not pinned by hash: odiglet/Dockerfile:139: pin your Docker image by updating gcr.io/distroless/base:latest to gcr.io/distroless/base:latest@sha256:27769871031f67460f1545a52dfacead6d18a9f197db77110cfc649ca2a91f44
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:4
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:19
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:35
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:52
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:62
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:90
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:100
Warn: containerImage not pinned by hash: odiglet/Dockerfile.rhel:143: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:dca8bc186bb579f36414c6ad28f1dbeda33e5cf0bd5fc1c51430cc578e25f819
Warn: containerImage not pinned by hash: odiglet/base.Dockerfile:1
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:3
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:18
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:34
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:50
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:59
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:87
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:97
Warn: containerImage not pinned by hash: odiglet/debug.Dockerfile:141: pin your Docker image by updating registry.fedoraproject.org/fedora-minimal:38 to registry.fedoraproject.org/fedora-minimal:38@sha256:46d9dd1088e30a5ae8cf0f3907ce97c11f59d189fc2067d96264568945a2923e
Warn: containerImage not pinned by hash: operator/Dockerfile:2
Warn: containerImage not pinned by hash: operator/Dockerfile:29: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: containerImage not pinned by hash: operator/Dockerfile.rhel:2
Warn: containerImage not pinned by hash: operator/Dockerfile.rhel:27: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-micro:latest to registry.access.redhat.com/ubi9/ubi-micro:latest@sha256:dca8bc186bb579f36414c6ad28f1dbeda33e5cf0bd5fc1c51430cc578e25f819
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/cpp-http-server/Dockerfile:2
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/cpp-http-server/Dockerfile:23: pin your Docker image by updating alpine:latest to alpine:latest@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-glibc.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-glibc.Dockerfile:8: pin your Docker image by updating mcr.microsoft.com/dotnet/aspnet:6.0 to mcr.microsoft.com/dotnet/aspnet:6.0@sha256:e70c493f8af7f95bf459cb2b15c7e7a6173228929c2b7a9a6836b19377890e78
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-musl.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-musl.Dockerfile:8: pin your Docker image by updating mcr.microsoft.com/dotnet/aspnet:6.0-alpine to mcr.microsoft.com/dotnet/aspnet:6.0-alpine@sha256:02a9f6b3d99095659228667f3c88aecf4fe331935b7b861a6c17f130b3cd97a1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-glibc.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-glibc.Dockerfile:7: pin your Docker image by updating mcr.microsoft.com/dotnet/aspnet:8.0 to mcr.microsoft.com/dotnet/aspnet:8.0@sha256:ab605d8d1b0886af2ef4bbaf5167fbe237670b6fd9829a05c4d08406afdd985e
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-musl.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-musl.Dockerfile:7: pin your Docker image by updating mcr.microsoft.com/dotnet/aspnet:8.0-alpine to mcr.microsoft.com/dotnet/aspnet:8.0-alpine@sha256:6faef52a037435524fcda33d94a23cada50eed3775849efa863bf0d45327403c
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-azul.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-azul.Dockerfile:6: pin your Docker image by updating azul/zulu-openjdk-alpine:17.0.12-jre-headless to azul/zulu-openjdk-alpine:17.0.12-jre-headless@sha256:12e335ed6d5cb4cd55ef6b5e2e769b2a77f25ced0270df1277bc2bca3dfd209e
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-latest-version.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-latest-version.Dockerfile:6: pin your Docker image by updating eclipse-temurin:latest to eclipse-temurin:latest@sha256:b997045cddee5aa5460aaec871775d8f24e5bea1af1592d8741bd5d4ff793e27
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-old-version.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-old-version.Dockerfile:6: pin your Docker image by updating eclipse-temurin:11-jre-jammy to eclipse-temurin:11-jre-jammy@sha256:4bd0627da97099c9d38c6e29fa852895f05b9da2ddced0de9b97085b4bc4c4c9
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-docker-env.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-docker-env.Dockerfile:6: pin your Docker image by updating eclipse-temurin:17.0.12_7-jre-jammy to eclipse-temurin:17.0.12_7-jre-jammy@sha256:6c4c0938462c9678fe380bf01c7da7f4242dc20f54362f24ced3bb70f6e0183a
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-manifest-env.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-manifest-env.Dockerfile:6: pin your Docker image by updating eclipse-temurin:17.0.12_7-jre-jammy to eclipse-temurin:17.0.12_7-jre-jammy@sha256:6c4c0938462c9678fe380bf01c7da7f4242dc20f54362f24ced3bb70f6e0183a
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-version.Dockerfile:1
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/java-http-server/java-supported-version.Dockerfile:6: pin your Docker image by updating eclipse-temurin:17.0.12_7-jre-jammy to eclipse-temurin:17.0.12_7-jre-jammy@sha256:6c4c0938462c9678fe380bf01c7da7f4242dc20f54362f24ced3bb70f6e0183a
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/dockerfile-env.Dockerfile:1: pin your Docker image by updating node:20.17.0-alpine to node:20.17.0-alpine@sha256:2d07db07a2df6830718ae2a47db6fedce6745f5bcd174c398f2acdda90a11c03
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/latest-version.Dockerfile:1: pin your Docker image by updating node:current-alpine to node:current-alpine@sha256:86703151a18fcd06258e013073508c4afea8e19cd7ed451554221dd00aea83fc
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/manifest-env.Dockerfile:1: pin your Docker image by updating node:20.17.0-alpine to node:20.17.0-alpine@sha256:2d07db07a2df6830718ae2a47db6fedce6745f5bcd174c398f2acdda90a11c03
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/minimum-version.Dockerfile:1: pin your Docker image by updating node:14.0.0-alpine to node:14.0.0-alpine@sha256:628ae0898c092799f09af3f15775b9d5f2feeafc1bb2485e68d577f3ea8f267e
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/unsupported-version.Dockerfile:1: pin your Docker image by updating node:8.17.0-alpine to node:8.17.0-alpine@sha256:38f7bf07ffd72ac612ec8c829cb20ad416518dbb679768d7733c93175453f4d4
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/nodejs-http-server/very-old-version.Dockerfile:1: pin your Docker image by updating node:8.17.0-alpine to node:8.17.0-alpine@sha256:38f7bf07ffd72ac612ec8c829cb20ad416518dbb679768d7733c93175453f4d4
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-alpine:2: pin your Docker image by updating python:3.10.15-alpine to python:3.10.15-alpine@sha256:039508c234f83314a3be8eed523f347f6f26816541be7caa4a9ef4a4bf1bfb66
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-latest:1: pin your Docker image by updating python to python@sha256:34dc8eb488136014caf530ec03a3a2403473a92d67a01a26256c365b5b2fc0d4
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-min-version:2: pin your Docker image by updating python:3.8.0-slim to python:3.8.0-slim@sha256:8e243f41e500238f78f7a29a81656114d3fe603d5c34079a462d090f71c4b225
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-not-supported-version:2: pin your Docker image by updating python:3.6-slim to python:3.6-slim@sha256:2cfebc27956e6a55f78606864d91fe527696f9e32a724e6f9702b5f9602d0474
Warn: containerImage not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-other-agent:1: pin your Docker image by updating python to python@sha256:34dc8eb488136014caf530ec03a3a2403473a92d67a01a26256c365b5b2fc0d4
Warn: pipCommand not pinned by hash: odiglet/Dockerfile:7
Warn: pipCommand not pinned by hash: odiglet/Dockerfile.rhel:8
Warn: pipCommand not pinned by hash: odiglet/debug.Dockerfile:7
Warn: goCommand not pinned by hash: odiglet/debug.Dockerfile:116
Warn: nugetCommand not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-glibc.Dockerfile:5: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net6-musl.Dockerfile:5: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-glibc.Dockerfile:4: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: tests/e2e/workload-lifecycle/services/dotnet-http-server/net8-musl.Dockerfile:4: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-alpine:5
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-alpine:10
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-latest:11
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-min-version:14
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-not-supported-version:8
Warn: pipCommand not pinned by hash: tests/e2e/workload-lifecycle/services/python-http-server/Dockerfile.python-other-agent:11
Warn: pipCommand not pinned by hash: .github/workflows/generated-docs.yaml:72
Warn: pipCommand not pinned by hash: .github/workflows/generated-docs.yaml:73
Warn: pipCommand not pinned by hash: .github/workflows/generated-docs.yaml:97
Warn: pipCommand not pinned by hash: .github/workflows/generated-docs.yaml:98
Info: 0 out of 67 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 48 third-party GitHubAction dependencies pinned
Info: 0 out of 78 containerImage dependencies pinned
Info: 0 out of 13 pipCommand dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned
Info: 0 out of 4 nugetCommand dependencies pinned