Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/fossa.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/fossa.yaml/release/v1.8?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/fossa.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/fossa.yaml/release/v1.8?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/fossa.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/fossa.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/git-actions-go-generate.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/git-actions-go-generate.yml/release/v1.8?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/git-actions-go-generate.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/git-actions-go-generate.yml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/git-actions-go-generate.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/git-actions-go-generate.yml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/stale.yml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-cni.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/test-cni.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-cni.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/test-cni.yaml/release/v1.8?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/update-readme.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/update-readme.yml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:137: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/workflow.yaml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/workflow.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/workflow.yaml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke/workflow.yaml/release/v1.8?enable=pin
Warn: containerImage not pinned by hash: Dockerfile.dapper:1: pin your Docker image by updating registry.suse.com/bci/golang:1.23 to registry.suse.com/bci/golang:1.23@sha256:e609c967242f2ba0deb74b2d5ae62b45542b168bd44433263ebbfd00cd56b778
Warn: downloadThenRun not pinned by hash: Dockerfile.dapper:8
Info: 1 out of 17 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned