Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): .ci/helm.sh:470
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:111: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:178: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:184: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:226: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:233: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bundle-release.yml:317: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/bundle-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentbot.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/documentbot.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/documentbot.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/documentbot.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/olm-verify.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/olm-verify.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/olm-verify.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/olm-verify.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/olm-verify.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/olm-verify.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/olm-verify.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/olm-verify.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/olm-verify.yml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/olm-verify.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/project.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/project.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/project.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project.yml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/project.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-note.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release-note.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-note.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release-note.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-function-runner.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-function-runner.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-function-runner.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-function-runner.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-function-runner.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-function-runner.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-helm-charts.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-helm-charts.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-helm-charts.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-helm-charts.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-helm-charts.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-helm-charts.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-helm-charts.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-helm-charts.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-helm-charts.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-helm-charts.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-helm-charts.yml:88: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-helm-charts.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-helm-charts.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-helm-charts.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-helm-charts.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-helm-charts.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-integration-skywalking-e2e.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-integration-skywalking-e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test-integration-skywalking-e2e.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-integration-skywalking-e2e.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/test-integration-skywalking-e2e.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/test-integration-skywalking-e2e.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:151: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy_scheduled_master.yml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/streamnative/function-mesh/trivy_scheduled_master.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:2
Warn: containerImage not pinned by hash: Dockerfile:27: pin your Docker image by updating gcr.io/distroless/static:nonroot to gcr.io/distroless/static:nonroot@sha256:c0f429e16b13e583da7e5a6ec20dd656d325d88e6819cafe0adb0828976529dc
Warn: containerImage not pinned by hash: images/pulsar-functions-base-runner/Dockerfile:3
Warn: containerImage not pinned by hash: images/pulsar-functions-base-runner/Dockerfile:4
Warn: containerImage not pinned by hash: images/pulsar-functions-base-runner/pulsarctl.Dockerfile:3
Warn: containerImage not pinned by hash: images/pulsar-functions-base-runner/pulsarctl.Dockerfile:4
Warn: containerImage not pinned by hash: images/pulsar-functions-go-runner/Dockerfile:1
Warn: containerImage not pinned by hash: images/pulsar-functions-go-runner/pulsarctl.Dockerfile:1
Warn: containerImage not pinned by hash: images/pulsar-functions-java-runner/Dockerfile:3
Warn: containerImage not pinned by hash: images/pulsar-functions-java-runner/Dockerfile:4
Warn: containerImage not pinned by hash: images/pulsar-functions-java-runner/pulsarctl.Dockerfile:3
Warn: containerImage not pinned by hash: images/pulsar-functions-java-runner/pulsarctl.Dockerfile:4
Warn: containerImage not pinned by hash: images/pulsar-functions-python-runner/Dockerfile:3
Warn: containerImage not pinned by hash: images/pulsar-functions-python-runner/Dockerfile:4
Warn: containerImage not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:4
Warn: containerImage not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:6
Warn: containerImage not pinned by hash: images/samples/go-function-samples/Dockerfile:2
Warn: containerImage not pinned by hash: images/samples/go-function-samples/Dockerfile:16
Warn: containerImage not pinned by hash: images/samples/java-function-samples/Dockerfile:2
Warn: containerImage not pinned by hash: images/samples/java-function-samples/Dockerfile:3
Warn: containerImage not pinned by hash: images/samples/pulsar-io-connector/pulsar-io-elasticsearch/Dockerfile:4
Warn: containerImage not pinned by hash: images/samples/pulsar-io-connector/pulsar-io-elasticsearch/Dockerfile:5
Warn: containerImage not pinned by hash: images/samples/python-function-samples/Dockerfile:2
Warn: containerImage not pinned by hash: images/samples/python-function-samples/Dockerfile:3
Warn: containerImage not pinned by hash: operator.Dockerfile:1: pin your Docker image by updating alpine:3.20 to alpine:3.20@sha256:de4fe7064d8f98419ea6b49190df1abbf43450c1702eeb864fe9ced453c1cc5f
Warn: containerImage not pinned by hash: redhat.Dockerfile:2
Warn: containerImage not pinned by hash: redhat.Dockerfile:28: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-micro:latest to registry.access.redhat.com/ubi8/ubi-micro:latest@sha256:084c06bf84ceb8ed8f868bd27e7fc6b2c83ae4e16f8e1f979dd7317961c7dd8a
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/Dockerfile:36
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/Dockerfile:36
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/Dockerfile:46
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/Dockerfile:48
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:49-54
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:56
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:56
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:57
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:57
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:68
Warn: pipCommand not pinned by hash: images/pulsar-functions-python-runner/pulsarctl.Dockerfile:70
Warn: downloadThenRun not pinned by hash: .github/workflows/project.yml:54
Info: 0 out of 26 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 42 third-party GitHubAction dependencies pinned
Info: 0 out of 27 containerImage dependencies pinned
Info: 0 out of 11 pipCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned