Warn: third-party GitHubAction not pinned by hash: .github/workflows/add-pr-label.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/add-pr-label.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cache-eviction.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/cache-eviction.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cache-setup.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/cache-setup.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/conformance-tests.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/conformance-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-gen.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/docs-gen.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-gen.yaml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/docs-gen.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/docs-gen.yaml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/docs-gen.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-gen.yaml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/docs-gen.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-gen.yaml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/docs-gen.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/docs-gen.yaml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/docs-gen.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_board.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/issue_board.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue_board.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/issue_board.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:429: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:522: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:541: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:415: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:443: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:457: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:471: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:569: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:595: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:273: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:279: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:398: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:504: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:211: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:217: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:485: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:154: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:322: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:351: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-tests.yaml:380: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/nightly-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-kubernetes-tests.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/pr-kubernetes-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-kubernetes-tests.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/pr-kubernetes-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-kubernetes-tests.yaml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/pr-kubernetes-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-kubernetes-tests.yaml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/pr-kubernetes-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-unit-tests.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/pr-unit-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-unit-tests.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/pr-unit-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-docs.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/push-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-docs.yaml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/push-docs.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-solo-apis-branch.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/push-solo-apis-branch.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-solo-apis-branch.yaml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/push-solo-apis-branch.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-solo-apis-branch.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/push-solo-apis-branch.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push-solo-apis-branch.yaml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/push-solo-apis-branch.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-solo-apis-branch.yaml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/push-solo-apis-branch.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/regression-tests.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/regression-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/regression-tests.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/regression-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/regression-tests.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/regression-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/regression-tests.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/regression-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stalebot.yaml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/stalebot.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-analysis.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/static-analysis.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/static-analysis.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/static-analysis.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/static-analysis.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/static-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-analysis.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/static-analysis.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/static-analysis.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/static-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy-analysis-scheduled.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/trivy-analysis-scheduled.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy-analysis-scheduled.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/trivy-analysis-scheduled.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy-analysis-scheduled.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/solo-io/gloo/trivy-analysis-scheduled.yaml/main?enable=pin
Warn: containerImage not pinned by hash: docs/content/guides/security/auth/custom_auth/Dockerfile:1: pin your Docker image by updating python:3 to python:3@sha256:8c55c44b9e81d537f8404d0000b7331863d134db87c1385dd0ec7fefff656495
Warn: containerImage not pinned by hash: docs/content/guides/security/tls/Dockerfile:1: pin your Docker image by updating alpine:3.17.6 to alpine:3.17.6@sha256:6e94b5cda2d6fd57d85abf81e81dabaea97a5885f919da676cc19d3551da4061
Warn: containerImage not pinned by hash: docs/examples/grpc-json-transcoding/bookstore/Dockerfile:1: pin your Docker image by updating alpine to alpine@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: docs/examples/grpc-passthrough-auth/Dockerfile:1
Warn: containerImage not pinned by hash: docs/examples/grpc-passthrough-auth/Dockerfile:7: pin your Docker image by updating alpine to alpine@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: docs/examples/http-passthrough-auth/Dockerfile:1
Warn: containerImage not pinned by hash: docs/examples/http-passthrough-auth/Dockerfile:7: pin your Docker image by updating alpine to alpine@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: docs/examples/session-affinity/Dockerfile:1: pin your Docker image by updating alpine:3.17.6 to alpine:3.17.6@sha256:6e94b5cda2d6fd57d85abf81e81dabaea97a5885f919da676cc19d3551da4061
Warn: containerImage not pinned by hash: docs/examples/xslt-guide/Dockerfile:1: pin your Docker image by updating alpine:3.17.6 to alpine:3.17.6@sha256:6e94b5cda2d6fd57d85abf81e81dabaea97a5885f919da676cc19d3551da4061
Warn: containerImage not pinned by hash: example/proxycontroller/Dockerfile:1: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: jobs/certgen/cmd/Dockerfile:3
Warn: containerImage not pinned by hash: jobs/certgen/cmd/Dockerfile.distroless:3
Warn: containerImage not pinned by hash: jobs/kubectl/Dockerfile:3
Warn: containerImage not pinned by hash: jobs/kubectl/Dockerfile:5
Warn: containerImage not pinned by hash: jobs/kubectl/Dockerfile.distroless:3
Warn: containerImage not pinned by hash: jobs/kubectl/Dockerfile.distroless:5
Warn: containerImage not pinned by hash: projects/accesslogger/cmd/Dockerfile:3
Warn: containerImage not pinned by hash: projects/accesslogger/cmd/Dockerfile.distroless:3
Warn: containerImage not pinned by hash: projects/discovery/cmd/Dockerfile:3
Warn: containerImage not pinned by hash: projects/discovery/cmd/Dockerfile.distroless:3
Warn: containerImage not pinned by hash: projects/distroless/Dockerfile:5
Warn: containerImage not pinned by hash: projects/distroless/Dockerfile:6
Warn: containerImage not pinned by hash: projects/distroless/Dockerfile:8
Warn: containerImage not pinned by hash: projects/distroless/Dockerfile:15
Warn: containerImage not pinned by hash: projects/distroless/Dockerfile.utils:5
Warn: containerImage not pinned by hash: projects/distroless/Dockerfile.utils:7
Warn: containerImage not pinned by hash: projects/envoyinit/cmd/Dockerfile.envoyinit:3
Warn: containerImage not pinned by hash: projects/envoyinit/cmd/Dockerfile.envoyinit.distroless:4
Warn: containerImage not pinned by hash: projects/envoyinit/cmd/Dockerfile.envoyinit.distroless:6
Warn: containerImage not pinned by hash: projects/examples/services/sleeper/Dockerfile:1: pin your Docker image by updating alpine:3.21.3 to alpine:3.21.3@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: containerImage not pinned by hash: projects/gloo/Dockerfile:13
Warn: containerImage not pinned by hash: projects/gloo/Dockerfile:39
Warn: containerImage not pinned by hash: projects/gloo/cmd/Dockerfile:3
Warn: containerImage not pinned by hash: projects/gloo/cmd/Dockerfile.distroless:4
Warn: containerImage not pinned by hash: projects/gloo/cmd/Dockerfile.distroless:6
Warn: containerImage not pinned by hash: projects/ingress/cmd/Dockerfile:3
Warn: containerImage not pinned by hash: projects/ingress/cmd/Dockerfile.distroless:3
Warn: containerImage not pinned by hash: projects/sds/cmd/Dockerfile:3
Warn: containerImage not pinned by hash: projects/sds/cmd/Dockerfile.distroless:3
Warn: containerImage not pinned by hash: test/kube2e/containers/testrunner/Dockerfile:2: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:ed1544e454989078f5dec1bfdabd8c5cc9c48e0705d07b678ab6ae3fb61952d2
Warn: containerImage not pinned by hash: test/kube2e/helper/docker/Dockerfile:1: pin your Docker image by updating cjimti/go-echo:latest to cjimti/go-echo:latest@sha256:ff9ac5cb2051d7ec0ba7b12b805550bbcb87966e9d5c288d75c18f87d9d861e9
Warn: containerImage not pinned by hash: test/kubernetes/testutils/helper/docker/Dockerfile:3: pin your Docker image by updating cjimti/go-echo:latest to cjimti/go-echo:latest@sha256:ff9ac5cb2051d7ec0ba7b12b805550bbcb87966e9d5c288d75c18f87d9d861e9
Warn: downloadThenRun not pinned by hash: projects/gateway2/istio.sh:8
Info: 0 out of 43 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 18 third-party GitHubAction dependencies pinned
Info: 0 out of 42 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned