Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-lint-and-test.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/chart-lint-and-test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-lint-and-test.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/chart-lint-and-test.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-lint-and-test.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/chart-lint-and-test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/command-dispatch.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/command-dispatch.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/command-dispatch.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/command-dispatch.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/pull-request.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pull-request.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/pull-request.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/release.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/release.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/release.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/release.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/release.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/release.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/run-acceptance-tests.yaml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/run-acceptance-tests.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/weekly-pulumi-update.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/weekly-pulumi-update.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/weekly-pulumi-update.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/weekly-pulumi-update.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/weekly-pulumi-update.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/weekly-pulumi-update.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/weekly-pulumi-update.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/pulumi/pulumi-kubernetes-operator/weekly-pulumi-update.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:2
Warn: containerImage not pinned by hash: Dockerfile:18
Warn: containerImage not pinned by hash: Dockerfile:31
Warn: containerImage not pinned by hash: Dockerfile:44: pin your Docker image by updating gcr.io/distroless/static-debian12:debug-nonroot to gcr.io/distroless/static-debian12:debug-nonroot@sha256:765ef30aff979959710073e7ba3b163d479a285d7d96d0020fca8c1501de48cb
Warn: goCommand not pinned by hash: .github/workflows/weekly-pulumi-update.yml:42
Info: 4 out of 18 GitHub-owned GitHubAction dependencies pinned
Info: 12 out of 29 third-party GitHubAction dependencies pinned
Info: 1 out of 5 containerImage dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned