Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/actionlint.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/actionlint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/automerge-dependabot.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/automerge-dependabot.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/changed-files.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/changed-files.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:138: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/checks.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/checks.yaml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/checks.yaml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/checks.yaml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/checks.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-feature-gated.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e-feature-gated.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-feature-gated.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e-feature-gated.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-feature-gated.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e-feature-gated.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-feature-gated.yaml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e-feature-gated.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-prometheus-v2.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e-prometheus-v2.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-prometheus-v2.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e-prometheus-v2.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-prometheus-v2.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e-prometheus-v2.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/publish.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/publish.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/publish.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/publish.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/publish.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/publish.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/stale.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-prom-version-upgrade.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/test-prom-version-upgrade.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-prom-version-upgrade.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/test-prom-version-upgrade.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-prom-version-upgrade.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/test-prom-version-upgrade.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-prom-version-upgrade.yaml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/test-prom-version-upgrade.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/unit.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/unit.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/unit.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/prometheus-operator/prometheus-operator/unit.yaml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:5
Warn: containerImage not pinned by hash: Dockerfile:18
Warn: containerImage not pinned by hash: cmd/admission-webhook/Dockerfile:5
Warn: containerImage not pinned by hash: cmd/admission-webhook/Dockerfile:18
Warn: containerImage not pinned by hash: cmd/prometheus-config-reloader/Dockerfile:5
Warn: containerImage not pinned by hash: cmd/prometheus-config-reloader/Dockerfile:18
Warn: containerImage not pinned by hash: scripts/tooling/Dockerfile:1
Warn: containerImage not pinned by hash: scripts/tooling/Dockerfile:27: pin your Docker image by updating golang:1.14 to golang:1.14@sha256:1a7173b5b9a3af3e29a5837e0b2027e1c438fd1b83bbee8f221355087ad416d6
Warn: goCommand not pinned by hash: scripts/tooling/Dockerfile:22
Warn: goCommand not pinned by hash: scripts/tooling/Dockerfile:23
Warn: downloadThenRun not pinned by hash: .github/workflows/actionlint.yml:19
Info: 0 out of 36 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 14 third-party GitHubAction dependencies pinned
Info: 0 out of 8 containerImage dependencies pinned
Info: 0 out of 2 goCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned