Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto_assign_prs.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/auto_assign_prs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/auto_label_prs.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/auto_label_prs.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/auto_request_review.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/auto_request_review.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-test-kind.yaml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/e2e-test-kind.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-trivy-scan.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/nightly-trivy-scan.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/nightly-trivy-scan.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/nightly-trivy-scan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/nightly-trivy-scan.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/nightly-trivy-scan.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-changelog-check.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-changelog-check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-ci-check.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-ci-check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-ci-check.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-ci-check.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-ci-check.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-ci-check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-codespell.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-codespell.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-codespell.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-codespell.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-containers.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-containers.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-containers.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-containers.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-containers.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-containers.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-goreleaser.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-goreleaser.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-linter-check.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-linter-check.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-linter-check.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-linter-check.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr-linter-check.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/pr-linter-check.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prow-action.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/prow-action.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push-builder.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push-builder.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/push.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/push.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/push.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/rebase.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/rebase.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/rebase.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/rebase.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale-issues.yml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/vmware-tanzu/velero/stale-issues.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:16
Warn: containerImage not pinned by hash: Dockerfile:52
Warn: containerImage not pinned by hash: Dockerfile:76: pin your Docker image by updating paketobuildpacks/run-jammy-tiny:latest to paketobuildpacks/run-jammy-tiny:latest@sha256:8e7fd259b498770a75ba146816434d9726a46c3b8371846a7b96d7febd89ca28
Warn: containerImage not pinned by hash: Dockerfile-Windows:18
Warn: containerImage not pinned by hash: Dockerfile-Windows:52
Warn: containerImage not pinned by hash: hack/build-image/Dockerfile:15: pin your Docker image by updating golang:1.23-bookworm to golang:1.23-bookworm@sha256:0b4f8c5d414756a53ba0e4d235151f9b246552e512c3feaad5f9a3251376b279
Warn: containerImage not pinned by hash: site/Dockerfile:1: pin your Docker image by updating klakegg/hugo:0.73.0-ext-ubuntu to klakegg/hugo:0.73.0-ext-ubuntu@sha256:bc1a00d1bc78738250923b97111bf21d135a48b96fab3c21c818842158a19abb
Warn: downloadThenRun not pinned by hash: hack/build-image/Dockerfile:97
Info: 0 out of 25 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 17 third-party GitHubAction dependencies pinned
Info: 0 out of 7 containerImage dependencies pinned
Info: 4 out of 4 goCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned