Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/license-checker.yml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/license-checker.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:119: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:136: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:170: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reviewdog.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/mosn/mosn/reviewdog.yml/master?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:6
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:20
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:25
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:34
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:65
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:70
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:75
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:84
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:95
Warn: containerImage not pinned by hash: build/contrib/builder/image/Dockerfile:1
Warn: containerImage not pinned by hash: build/contrib/builder/image/Dockerfile:20: pin your Docker image by updating centos:centos7 to centos:centos7@sha256:be65f488b7764ad3638f236b7b515b3678369a5124c47b8d32916d6487418ea4
Warn: containerImage not pinned by hash: build/contrib/builder/rpm/Dockerfile:1: pin your Docker image by updating centos:centos7 to centos:centos7@sha256:be65f488b7764ad3638f236b7b515b3678369a5124c47b8d32916d6487418ea4
Warn: containerImage not pinned by hash: build/contrib/builder/wasm/Dockerfile:1: pin your Docker image by updating golang:1.18 to golang:1.18@sha256:50c889275d26f816b5314fc99f55425fa76b18fcaf16af255f5d57f09e1f48da
Warn: containerImage not pinned by hash: examples/codes/filter/dubbo/install/build/Dockerfile:1: pin your Docker image by updating istio/proxyv2:1.7.3 to istio/proxyv2:1.7.3@sha256:6169d096fe60f128f1311f76c97ee1c3e5d760a45042d5c9182492745d34c658
Warn: containerImage not pinned by hash: examples/codes/mosn-extensions/plugin/filter/python/Dockerfile:1: pin your Docker image by updating centos:7 to centos:7@sha256:be65f488b7764ad3638f236b7b515b3678369a5124c47b8d32916d6487418ea4
Warn: containerImage not pinned by hash: examples/codes/xds-server-sample/Dockerfile:1
Warn: containerImage not pinned by hash: pkg/module/http2/Dockerfile:9: pin your Docker image by updating ubuntu:trusty to ubuntu:trusty@sha256:64483f3496c1373bfd55348e88694d1c4d0c9b660dee6bfef5e12f43b9933b30
Warn: containerImage not pinned by hash: pkg/networkextention/build/image/envoy/Dockerfile:1: pin your Docker image by updating mosnio/mosn-network-envoy-sdk:1.16.2 to mosnio/mosn-network-envoy-sdk:1.16.2@sha256:10933e2ae2ccc2f0acb45b2d6966bbf680c7991ee8daae830c4f2ba3d55fc0d2
Warn: npmCommand not pinned by hash: .devcontainer/Dockerfile:119
Warn: pipCommand not pinned by hash: build/contrib/builder/image/Dockerfile:36
Warn: pipCommand not pinned by hash: build/contrib/builder/image/Dockerfile:37
Warn: pipCommand not pinned by hash: examples/codes/mosn-extensions/plugin/filter/python/Dockerfile:11-18
Warn: pipCommand not pinned by hash: examples/codes/mosn-extensions/plugin/filter/python/Dockerfile:11-18
Warn: downloadThenRun not pinned by hash: .github/workflows/reviewdog.yml:92
Warn: goCommand not pinned by hash: .github/workflows/reviewdog.yml:25
Info: 0 out of 15 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 2 third-party GitHubAction dependencies pinned
Info: 0 out of 18 containerImage dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 4 pipCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned
Info: 0 out of 1 goCommand dependencies pinned