Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): vendor/sigs.k8s.io/controller-runtime/Makefile:0
Warn: third-party GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/codeql-analysis.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/develop-image.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/develop-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/develop-image.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/develop-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/develop-image.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/develop-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/develop-image.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/develop-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/develop-image.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/develop-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/develop-image.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/develop-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/linter.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/linter.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linter.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/linter.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linter.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/linter.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/linter.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/linter.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/linter.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/linter.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linter.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/linter.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linter.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/linter.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/redhat-image.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/redhat-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/redhat-image.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/redhat-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/redhat-image.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/redhat-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-image.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/release-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-image.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/release-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-image.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/release-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-image.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/release-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-image.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/release-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-image.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/release-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-image.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/release-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-image.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/release-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-build.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/test-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-build.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/test-build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-build.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/test-build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-build.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/test-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-build.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/test-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-build.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/test-build.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-build.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/test-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-build.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/storageos/api-manager/test-build.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:2
Warn: containerImage not pinned by hash: Dockerfile:13: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal to registry.access.redhat.com/ubi8/ubi-minimal@sha256:fceb1f445ccd61a60d91d404fd76dbebaf3403e6cc2219cf6d6af4fd4bf7df6a
Warn: containerImage not pinned by hash: manifests.Dockerfile:2: pin your Docker image by updating nixery.dev/shell/remake/go/gcc/kustomize:build to nixery.dev/shell/remake/go/gcc/kustomize:build@sha256:7ee21948cda122b90cf31c74c6f3dfa4bd6a5694bf657f574dc2bc875faab43e
Warn: containerImage not pinned by hash: manifests.Dockerfile:15: pin your Docker image by updating busybox:1.33.1 to busybox:1.33.1@sha256:f7ca5a32c10d51aeda3b4d01c61c6061f497893d7f6628b92f822f7117182a57
Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10
Info: 0 out of 17 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 20 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned