Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/changelog-label.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/changelog-label.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/check-fast-forward.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/check-fast-forward.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/fast-forward.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/fast-forward.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/golang-image.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/golang-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golang-image.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/golang-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golang-image.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/golang-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/golang-image.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/golang-image.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/main.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/main.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/main.yml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/main.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/main.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prepare-release.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/prepare-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prepare-release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/prepare-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-clair.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/update-clair.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-clair.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/update-clair.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-clair.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/update-clair.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/update.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/update.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/update.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/updater-check-failures.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/updater-check-failures.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/updater-check.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/updater-check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/updater-check.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/quay/claircore/updater-check.yml/main?enable=pin
Warn: containerImage not pinned by hash: etc/Dockerfile:2
Info: 0 out of 18 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 15 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned