Info: Possibly incomplete results: error parsing shell code: = must follow a name: .github/workflows/freshen-images/build.sh:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/deploy.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/deploy.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/deploy.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/freshen-images.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/freshen-images.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/freshen-images.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/freshen-images.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/freshen-images.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/freshen-images.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/freshen-images.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/freshen-images.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/freshen-images.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/freshen-images.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/integration.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/olm-check.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/olm-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rerun.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/rerun.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-go.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-go.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-go.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-helm.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-helm.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-helm.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-helm.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-helm.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-helm.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-sample-go.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-sample-go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-sample-go.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-sample-go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-sample-go.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-sample-go.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-sanity.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-sanity.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-sanity.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-sanity.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-sanity.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-sanity.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-sanity.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-sanity.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-sanity.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-sdk/test-sanity.yml/master?enable=pin
Warn: containerImage not pinned by hash: images/custom-scorecard-tests/Dockerfile:2
Warn: containerImage not pinned by hash: images/custom-scorecard-tests/Dockerfile:20: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal:9.6 to registry.access.redhat.com/ubi9/ubi-minimal:9.6@sha256:e12131db2e2b6572613589a94b7f615d4ac89d94f859dad05908aeb478fb090f
Warn: containerImage not pinned by hash: images/helm-operator/Dockerfile:2
Warn: containerImage not pinned by hash: images/helm-operator/Dockerfile:20: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal:9.6 to registry.access.redhat.com/ubi9/ubi-minimal:9.6@sha256:e12131db2e2b6572613589a94b7f615d4ac89d94f859dad05908aeb478fb090f
Warn: containerImage not pinned by hash: images/operator-sdk/Dockerfile:2
Warn: containerImage not pinned by hash: images/operator-sdk/Dockerfile:20: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal:9.6 to registry.access.redhat.com/ubi9/ubi-minimal:9.6@sha256:e12131db2e2b6572613589a94b7f615d4ac89d94f859dad05908aeb478fb090f
Warn: containerImage not pinned by hash: images/scorecard-storage/Dockerfile:1: pin your Docker image by updating docker.io/busybox:1.36 to docker.io/busybox:1.36@sha256:7edf5efe6b86dbf01ccc3c76b32a37a8e23b84e6bad81ce8ae8c221fa456fda8
Warn: containerImage not pinned by hash: images/scorecard-test-kuttl/Dockerfile:2
Warn: containerImage not pinned by hash: images/scorecard-test-kuttl/Dockerfile:22: pin your Docker image by updating kudobuilder/kuttl:v0.15.0 to kudobuilder/kuttl:v0.15.0@sha256:cc724bf3adb9a770cd8a344af066a1fb82287ca1da6c9d6f1e92e395f27adb00
Warn: containerImage not pinned by hash: images/scorecard-test/Dockerfile:2
Warn: containerImage not pinned by hash: images/scorecard-test/Dockerfile:20: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal:9.6 to registry.access.redhat.com/ubi9/ubi-minimal:9.6@sha256:e12131db2e2b6572613589a94b7f615d4ac89d94f859dad05908aeb478fb090f
Warn: containerImage not pinned by hash: images/scorecard-untar/Dockerfile:1: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi:9.5 to registry.access.redhat.com/ubi9/ubi:9.5@sha256:d07a5e080b8a9b3624d3c9cfbfada9a6baacd8e6d4065118f0e80c71ad518044
Warn: goCommand not pinned by hash: hack/generate/olm_bindata.sh:41
Info: 0 out of 26 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 14 third-party GitHubAction dependencies pinned
Info: 0 out of 12 containerImage dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned