Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): Dockerfile-windows.dapper:6-13
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): Dockerfile-windows.dapper:15-31
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): Dockerfile-windows.dapper:34-47
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): package/windows/Dockerfile.agent:19-24
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): package/windows/Dockerfile.agent:26-33
Info: Possibly incomplete results: error parsing shell code: a command can only contain words and redirects; encountered (: tests/validation/tests/Dockerfiles/windows/metrics/Dockerfile:5-18
Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): tests/validation/tests/Dockerfiles/windows/nginx/Dockerfile:6-10
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/controller-test.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/controller-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/controller-test.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/controller-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/fossa.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/fossa.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/fossa.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/fossa.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/fossa.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/fossa.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-get.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/go-get.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go-get.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/go-get.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-get.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/go-get.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-get.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/go-get.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:136: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:138: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:179: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:196: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:214: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/hotfix-release.yml:218: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/hotfix-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-tests.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/integration-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-tests.yml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/integration-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/integration-tests.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/integration-tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/promote-to-stable.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/promote-to-stable.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/promote-to-stable.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/promote-to-stable.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/promote-to-stable.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/promote-to-stable.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/promote-to-stable.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/promote-to-stable.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/promote-to-stable.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/promote-to-stable.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/provisioning-tests.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/provisioning-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/provisioning-tests.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/provisioning-tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/pull-request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/pull-request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/pull-request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pull-request.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/pull-request.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:164: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:187: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:200: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:208: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:213: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:232: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:256: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:266: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:341: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:345: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:347: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:353: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:492: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:496: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:499: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:505: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:511: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:536: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:542: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:564: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:570: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:295: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:297: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:305: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:311: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:376: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:380: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:382: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:388: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:439: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:444: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:450: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:456: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:461: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:463: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:465: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:471: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:620: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:634: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:656: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-release.yml:662: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-release.yml:686: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/push-release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:136: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:151: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:192: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:212: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:216: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/release.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/replace-env-value.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/replace-env-value.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/replace-env-value.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/replace-env-value.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/stale.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/system-agent-upgrade.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/system-agent-upgrade.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/system-agent-upgrade.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/system-agent-upgrade.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/system-agent-upgrade.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/system-agent-upgrade.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/system-agent-upgrade.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/system-agent-upgrade.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-test.yml:9: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/unit-test.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/validate.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/validate.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-generated-code-changes.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/verify-generated-code-changes.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-generated-code-changes.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/verify-generated-code-changes.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify-generated-code-changes.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rancher/verify-generated-code-changes.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile-windows.dapper:1: pin your Docker image by updating library/golang:1.24 to library/golang:1.24@sha256:39d9e7d9c5d9c9e4baf0d8fff579f06d5032c0f4425cdec9e86732e8e4e374dc
Warn: containerImage not pinned by hash: Dockerfile.dapper:1: pin your Docker image by updating registry.suse.com/bci/golang:1.24 to registry.suse.com/bci/golang:1.24@sha256:484d0349323d87f1f83239d2533de4048549f28aa0a38929a2000b765b1f104a
Warn: containerImage not pinned by hash: package/Dockerfile:11
Warn: containerImage not pinned by hash: package/Dockerfile:15
Warn: containerImage not pinned by hash: package/Dockerfile:27
Warn: containerImage not pinned by hash: package/Dockerfile:36
Warn: containerImage not pinned by hash: package/Dockerfile:45
Warn: containerImage not pinned by hash: package/Dockerfile:48
Warn: containerImage not pinned by hash: package/Dockerfile:54
Warn: containerImage not pinned by hash: package/Dockerfile:63
Warn: containerImage not pinned by hash: package/Dockerfile:72
Warn: containerImage not pinned by hash: package/Dockerfile:81
Warn: containerImage not pinned by hash: package/Dockerfile:87
Warn: containerImage not pinned by hash: package/Dockerfile:99
Warn: containerImage not pinned by hash: package/Dockerfile:303
Warn: containerImage not pinned by hash: package/Dockerfile:318
Warn: containerImage not pinned by hash: package/Dockerfile:329
Warn: containerImage not pinned by hash: package/Dockerfile:344
Warn: containerImage not pinned by hash: package/Dockerfile:356
Warn: containerImage not pinned by hash: package/Dockerfile:389
Warn: containerImage not pinned by hash: package/Dockerfile.installer:3
Warn: containerImage not pinned by hash: package/Dockerfile.installer:5
Warn: containerImage not pinned by hash: package/windows/Dockerfile.agent:5
Warn: containerImage not pinned by hash: package/windows/Dockerfile.agent:17
Warn: containerImage not pinned by hash: tests/scripts/custodian/Dockerfile:1: pin your Docker image by updating ubuntu:24.04 to ubuntu:24.04@sha256:6015f66923d7afbc53558d7ccffd325d43b4e249f41a6e93eef074c9505d2233
Warn: containerImage not pinned by hash: tests/v2/codecoverage/Dockerfile.buildcodecoverage:1: pin your Docker image by updating registry.suse.com/bci/golang:1.24 to registry.suse.com/bci/golang:1.24@sha256:484d0349323d87f1f83239d2533de4048549f28aa0a38929a2000b765b1f104a
Warn: containerImage not pinned by hash: tests/v2/codecoverage/Dockerfile.codecoverage:1: pin your Docker image by updating registry.suse.com/bci/golang:1.24 to registry.suse.com/bci/golang:1.24@sha256:484d0349323d87f1f83239d2533de4048549f28aa0a38929a2000b765b1f104a
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile:1
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile:4
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile:18
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile:232
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile:247
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile:272
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile.agent:8
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile.agent:30
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile.agent:32
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile.agent:34
Warn: containerImage not pinned by hash: tests/v2/codecoverage/package/Dockerfile.agent:48
Warn: containerImage not pinned by hash: tests/validation/Dockerfile.rke:1: pin your Docker image by updating python:3.11 to python:3.11@sha256:aeb7cf72ae3acee0a0af0a6e09023201a103d359cf64da9fcd06bdfdef98c24f
Warn: containerImage not pinned by hash: tests/validation/Dockerfile.v3api:1: pin your Docker image by updating python:3.11 to python:3.11@sha256:aeb7cf72ae3acee0a0af0a6e09023201a103d359cf64da9fcd06bdfdef98c24f
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/testcontainer/Dockerfile:1: pin your Docker image by updating nginx to nginx@sha256:c15da6c91de8d2f436196f3a768483ad32c258ed4e1beb3d367a27ed67253e66
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/unprivileged-testcontainer/Dockerfile:1
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/windows/metrics/Dockerfile:3
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/windows/nginx/Dockerfile:3
Warn: containerImage not pinned by hash: tests/validation/tests/Dockerfiles/windows/testcontainer/Dockerfile:3
Warn: downloadThenRun not pinned by hash: Dockerfile.dapper:22-24
Warn: downloadThenRun not pinned by hash: Dockerfile.dapper:27-29
Warn: downloadThenRun not pinned by hash: tests/scripts/custodian/Dockerfile:38
Warn: pipCommand not pinned by hash: tests/scripts/custodian/Dockerfile:42
Warn: downloadThenRun not pinned by hash: tests/v2/codecoverage/Dockerfile.buildcodecoverage:13-17
Warn: goCommand not pinned by hash: tests/v2/codecoverage/Dockerfile.codecoverage:20-24
Warn: goCommand not pinned by hash: tests/v2/codecoverage/Dockerfile.codecoverage:20-24
Warn: goCommand not pinned by hash: tests/v2/codecoverage/Dockerfile.codecoverage:20-24
Warn: pipCommand not pinned by hash: tests/validation/Dockerfile.rke:10-18
Warn: pipCommand not pinned by hash: tests/validation/Dockerfile.rke:10-18
Warn: pipCommand not pinned by hash: tests/validation/Dockerfile.v3api:19-49
Warn: pipCommand not pinned by hash: tests/validation/Dockerfile.v3api:19-49
Warn: goCommand not pinned by hash: tests/controllers/run_controller_tests.sh:5
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:76
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:80
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:82
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:89
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:93
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/install_k3s_master.sh:95
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:64
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:68
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:70
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:76
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:80
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/master/join_k3s_master.sh:82
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/worker/join_k3s_agent.sh:38
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/worker/join_k3s_agent.sh:42
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/k3s/worker/join_k3s_agent.sh:44
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/install_rke2_master.sh:57
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/install_rke2_master.sh:59
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/install_rke2_master.sh:76
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/join_rke2_master.sh:58
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/join_rke2_master.sh:60
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/master/join_rke2_master.sh:77
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/worker/join_rke2_agent.sh:55
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/worker/join_rke2_agent.sh:57
Warn: downloadThenRun not pinned by hash: tests/validation/tests/v3_api/resource/terraform/rke2/worker/join_rke2_agent.sh:72
Warn: downloadThenRun not pinned by hash: .github/workflows/integration-tests.yml:79
Warn: pipCommand not pinned by hash: .github/workflows/integration-tests.yml:89
Warn: pipCommand not pinned by hash: .github/workflows/integration-tests.yml:90
Warn: downloadThenRun not pinned by hash: .github/workflows/provisioning-tests.yml:92
Warn: pipCommand not pinned by hash: .github/workflows/validate.yml:28
Warn: pipCommand not pinned by hash: .github/workflows/validate.yml:29
Info: 0 out of 67 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 59 third-party GitHubAction dependencies pinned
Info: 0 out of 45 containerImage dependencies pinned
Info: 0 out of 30 downloadThenRun dependencies pinned
Info: 0 out of 9 pipCommand dependencies pinned
Info: 5 out of 9 goCommand dependencies pinned