Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): Dockerfile-windows.dapper:6-13
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): Dockerfile-windows.dapper:15-31
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): Dockerfile-windows.dapper:34-47
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): package/windows/Dockerfile.agent:6-11
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): package/windows/Dockerfile.agent:13-20
Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: tests/validation/tests/Dockerfiles/windows/metrics/Dockerfile:5-18
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): tests/validation/tests/Dockerfiles/windows/nginx/Dockerfile:6-10
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-get.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/go-get.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-get.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/go-get.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/replace-env-value.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/replace-env-value.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/replace-env-value.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/replace-env-value.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/stale.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-readme.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/update-readme.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-readme.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/update-readme.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-generated-code-changes.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/verify-generated-code-changes.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-generated-code-changes.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/verify-generated-code-changes.yml/release/v2.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-generated-code-changes.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/pennyscissors/rancher/verify-generated-code-changes.yml/release/v2.8?enable=pin
Warn: containerImage not pinned by hash: Dockerfile-windows.dapper:1: pin your Docker image by updating library/golang:1.20.0 to library/golang:1.20.0@sha256:63c5d6404238855365d5bac79ed0564a1e1d3bcda916dfc87cfb32d027e28e1a
Warn: containerImage not pinned by hash: Dockerfile.dapper:1: pin your Docker image by updating registry.suse.com/bci/golang:1.20 to registry.suse.com/bci/golang:1.20@sha256:b3db4905f4f89fa367098a68646388162c1f7f579de7076443fb55e7cd0c8277
Warn: containerImage not pinned by hash: package/Dockerfile:1: pin your Docker image by updating registry.suse.com/bci/bci-base:15.5 to registry.suse.com/bci/bci-base:15.5@sha256:b1df9c4c96fea213cf91cd12a1ec9f62427d6418b0c5dccb99a5be6b0fd59479
Warn: containerImage not pinned by hash: package/Dockerfile.agent:3
Warn: containerImage not pinned by hash: package/Dockerfile.agent:5: pin your Docker image by updating registry.suse.com/bci/bci-base:15.5 to registry.suse.com/bci/bci-base:15.5@sha256:b1df9c4c96fea213cf91cd12a1ec9f62427d6418b0c5dccb99a5be6b0fd59479
Warn: containerImage not pinned by hash: package/Dockerfile.installer:3
Warn: containerImage not pinned by hash: package/windows/Dockerfile.agent:3
Warn: containerImage not pinned by hash: tests/scripts/custodian/Dockerfile:1: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:ed1544e454989078f5dec1bfdabd8c5cc9c48e0705d07b678ab6ae3fb61952d2
Warn: containerImage not pinned by hash: tests/v2/codecoverage/Dockerfile.buildcodecoverage:1: pin your Docker image by updating registry.suse.com/bci/golang:1.20 to registry.suse.com/bci/golang:1.20@sha256:b3db4905f4f89fa367098a68646388162c1f7f579de7076443fb55e7cd0c8277
Warn: containerImage not pinned by hash: tests/v2/codecoverage/Dockerfile.codecoverage:1: pin your Docker image by updating registry.suse.com/bci/golang:1.20 to registry.suse.com/bci/golang:1.20@sha256:b3db4905f4f89fa367098a68646388162c1f7f579de7076443fb55e7cd0c8277
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile:1: pin your Docker image by updating registry.suse.com/bci/bci-base:15.5 to registry.suse.com/bci/bci-base:15.5@sha256:b1df9c4c96fea213cf91cd12a1ec9f62427d6418b0c5dccb99a5be6b0fd59479
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile.agent:3
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile.agent:5: pin your Docker image by updating registry.suse.com/bci/bci-base:15.5 to registry.suse.com/bci/bci-base:15.5@sha256:b1df9c4c96fea213cf91cd12a1ec9f62427d6418b0c5dccb99a5be6b0fd59479
Warn: containerImage not pinned by hash: tests/v2/validation/Dockerfile.e2e:1: pin your Docker image by updating registry.suse.com/bci/golang:1.20 to registry.suse.com/bci/golang:1.20@sha256:b3db4905f4f89fa367098a68646388162c1f7f579de7076443fb55e7cd0c8277
Warn: containerImage not pinned by hash: tests/v2/validation/Dockerfile.validation:1: pin your Docker image by updating golang:1.20 to golang:1.20@sha256:8f9af7094d0cb27cc783c697ac5ba25efdc4da35f8526db21f7aebb0b0b4f18a
Warn: containerImage not pinned by hash: tests/validation/Dockerfile.rke:1: pin your Docker image by updating python:3.7.0 to python:3.7.0@sha256:10608fb357a18383f792efbf7472ec6d2e166dad62efc0d7c409ef2777aaafd0
Warn: containerImage not pinned by hash: tests/validation/Dockerfile.v3api:1: pin your Docker image by updating python:3.7.12 to python:3.7.12@sha256:b48983bebd0fe1c09639fa008e4cb51aac6277af6c6762fc58ac9d2cb7fc24ef
Warn: containerImage not pinned by hash: tests/validation/images/container-utils/Dockerfile:1: pin your Docker image by updating ubuntu:16.04 to ubuntu:16.04@sha256:1f1a2d56de1d604801a9671f301190704c25d604a416f59e03c04f5c6ffee0d6
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/testcontainer/Dockerfile:1: pin your Docker image by updating nginx to nginx@sha256:124b44bfc9ccd1f3cedf4b592d4d1e8bddb78b51ec2ed5056c52d3692baebc19
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/unprivileged-testcontainer/Dockerfile:1
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/windows/metrics/Dockerfile:3
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/windows/nginx/Dockerfile:3
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/windows/testcontainer/Dockerfile:3
Warn: downloadThenRun not pinned by hash: Dockerfile.dapper:26-28
Warn: downloadThenRun not pinned by hash: Dockerfile.dapper:30-33
Warn: downloadThenRun not pinned by hash: Dockerfile.dapper:30-33
Warn: downloadThenRun not pinned by hash: tests/scripts/custodian/Dockerfile:31
Warn: pipCommand not pinned by hash: tests/scripts/custodian/Dockerfile:34
Warn: downloadThenRun not pinned by hash: tests/v2/codecoverage/Dockerfile.buildcodecoverage:13-17
Warn: goCommand not pinned by hash: tests/v2/codecoverage/Dockerfile.codecoverage:20-24
Warn: goCommand not pinned by hash: tests/v2/codecoverage/Dockerfile.codecoverage:20-24
Warn: goCommand not pinned by hash: tests/v2/codecoverage/Dockerfile.codecoverage:20-24
Warn: goCommand not pinned by hash: tests/v2/validation/Dockerfile.e2e:19-21
Warn: goCommand not pinned by hash: tests/v2/validation/Dockerfile.validation:16-17
Warn: pipCommand not pinned by hash: tests/validation/Dockerfile.rke:10-18
Warn: pipCommand not pinned by hash: tests/validation/Dockerfile.rke:10-18
Warn: pipCommand not pinned by hash: tests/validation/Dockerfile.v3api:19-49
Warn: pipCommand not pinned by hash: tests/validation/Dockerfile.v3api:19-49
Warn: pipCommand not pinned by hash: tests/validation/images/container-utils/Dockerfile:6-10
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:63
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:67
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:69
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:76
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:80
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:82
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:51
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:55
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:57
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:63
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:67
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:69
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/worker/join_k3s_agent.sh:38
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/worker/join_k3s_agent.sh:42
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/worker/join_k3s_agent.sh:44
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/install_rke2_master.sh:57
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/install_rke2_master.sh:59
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/install_rke2_master.sh:76
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/join_rke2_master.sh:58
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/join_rke2_master.sh:60
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/join_rke2_master.sh:77
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/worker/join_rke2_agent.sh:55
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/worker/join_rke2_agent.sh:57
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/worker/join_rke2_agent.sh:72
Info: 0 out of 10 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 23 containerImage dependencies pinned
Info: 0 out of 29 downloadThenRun dependencies pinned
Info: 4 out of 9 goCommand dependencies pinned
Info: 0 out of 6 pipCommand dependencies pinned