Info: Possibly incomplete results: error parsing shell code: reached EOF without closing quote ": hack/e2e/aks_2.sh:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aks-addon-tests.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/aks-addon-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aks-addon-tests.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/aks-addon-tests.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/aks-addon-tests.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/aks-addon-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/chart.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/chart.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release-pull-request.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/create-release-pull-request.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release-pull-request.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/create-release-pull-request.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-release-pull-request.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/create-release-pull-request.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/create-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/create-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/create-release.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/create-release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-release.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/create-release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/e2e-tests.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/lint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/lint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/markdown-link-check.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/markdown-link-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/markdown-link-check.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/markdown-link-check.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-title-lint.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/pr-title-lint.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-image.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/publish-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-image.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/publish-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-init-container-image.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/publish-init-container-image.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-init-container-image.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/publish-init-container-image.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/tests.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/virtual-kubelet/azure-aci/tests.yml/master?enable=pin
Warn: containerImage not pinned by hash: docker/init-container/Dockerfile:1
Warn: containerImage not pinned by hash: docker/init-container/Dockerfile:24: pin your Docker image by updating gcr.io/distroless/static to gcr.io/distroless/static@sha256:3f2b64ef97bd285e36132c684e6b2ae8f2723293d09aae046196cca64251acac
Warn: containerImage not pinned by hash: docker/virtual-kubelet/Dockerfile:1
Warn: containerImage not pinned by hash: docker/virtual-kubelet/Dockerfile:27: pin your Docker image by updating gcr.io/distroless/static to gcr.io/distroless/static@sha256:3f2b64ef97bd285e36132c684e6b2ae8f2723293d09aae046196cca64251acac
Info: 4 out of 22 GitHub-owned GitHubAction dependencies pinned
Info: 3 out of 13 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned