Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/fossa.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/fossa.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/fossa.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/fossa.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/fossa.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/fossa.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-install.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/nightly-install.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-install.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/nightly-install.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/pr.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/pr.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/pr.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:161: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:193: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:201: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:211: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:238: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:246: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:283: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:287: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:294: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/spellcheck.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/spellcheck.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/spellcheck.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/spellcheck.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/stale.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:187: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:193: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:208: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:126: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-suite.yaml:160: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/test-suite.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/trivy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/trivy.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/trivy.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/trivy.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yaml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/trivy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/trivy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/trivy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unittest.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/unittest.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/unittest.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/unittest.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/updatecli.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/updatecli.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/updatecli.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/updatecli.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/updatecli.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/rancher/rke2/updatecli.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:4
Warn: containerImage not pinned by hash: Dockerfile:28
Warn: containerImage not pinned by hash: Dockerfile:32
Warn: containerImage not pinned by hash: Dockerfile:85
Warn: containerImage not pinned by hash: Dockerfile:106
Warn: containerImage not pinned by hash: Dockerfile:119
Warn: containerImage not pinned by hash: Dockerfile:120
Warn: containerImage not pinned by hash: Dockerfile:121
Warn: containerImage not pinned by hash: Dockerfile:122
Warn: containerImage not pinned by hash: Dockerfile:149
Warn: containerImage not pinned by hash: Dockerfile.docs:1: pin your Docker image by updating squidfunk/mkdocs-material to squidfunk/mkdocs-material@sha256:f6c81d538499f5755c8d1486f0abcda50bb631be391890ef823fcba18803114a
Warn: containerImage not pinned by hash: Dockerfile.windows:1
Warn: containerImage not pinned by hash: Dockerfile.windows:8
Warn: containerImage not pinned by hash: Dockerfile.windows:40
Warn: containerImage not pinned by hash: Dockerfile.windows:41
Warn: pipCommand not pinned by hash: Dockerfile:54
Warn: downloadThenRun not pinned by hash: Dockerfile:55
Warn: goCommand not pinned by hash: Dockerfile:97
Warn: goCommand not pinned by hash: Dockerfile:98
Warn: pipCommand not pinned by hash: Dockerfile.docs:2
Warn: downloadThenRun not pinned by hash: Dockerfile.windows:36
Warn: pipCommand not pinned by hash: .github/workflows/spellcheck.yaml:21
Warn: pipCommand not pinned by hash: .github/workflows/spellcheck.yaml:22
Info: 0 out of 36 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 21 third-party GitHubAction dependencies pinned
Info: 0 out of 15 containerImage dependencies pinned
Info: 0 out of 4 pipCommand dependencies pinned
Info: 0 out of 2 downloadThenRun dependencies pinned
Info: 0 out of 2 goCommand dependencies pinned