Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docker.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/docker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docker.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/docker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/golangci-lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golangci-lint.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/golangci-lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/license-checker.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/license-checker.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/license-checker.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/license-checker.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/testing.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/testing.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/testing.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/testing.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/testing.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/polarismesh/polaris-controller/testing.yml/main?enable=pin
Warn: containerImage not pinned by hash: docker/Dockerfile:16: pin your Docker image by updating alpine:latest to alpine:latest@sha256:8a1f59ffb675680d47db6337b49d22281a139e9d709335b492be023728e11715
Warn: containerImage not pinned by hash: sidecar/envoy-bootstrap-config-generator/Dockerfile:16: pin your Docker image by updating alpine:3.8 to alpine:3.8@sha256:2bb501e6173d9d006e56de5bce2720eb06396803300fe1687b58a7ff32bf4c14
Warn: containerImage not pinned by hash: sidecar/polaris-sidecar-init/Dockerfile:16: pin your Docker image by updating alpine:3.18.6 to alpine:3.18.6@sha256:11e21d7b981a59554b3f822c49f6e9f57b6068bb74f49c4cd5cc4c663c7e5160
Info: 0 out of 15 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 3 containerImage dependencies pinned