Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codespell.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/codespell.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/codespell.yml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/codespell.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/darwin.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/darwin.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/darwin.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/darwin.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/linux.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/linux.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pluto.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/pluto.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pluto.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/pluto.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/shellcheck.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/shellcheck.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/shellcheck.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/shellcheck.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static.yaml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/static.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/static.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/static.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/static.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/trivy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/trivy.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/trivy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/windows.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-sigs/blob-csi-driver/windows.yaml/master?enable=pin
Warn: containerImage not pinned by hash: pkg/blobplugin/Dockerfile:17
Warn: containerImage not pinned by hash: pkg/blobplugin/Dockerfile:19
Warn: containerImage not pinned by hash: pkg/blobplugin/Dockerfile:42
Warn: downloadThenRun not pinned by hash: hack/verify-helm-chart-files.sh:52
Warn: downloadThenRun not pinned by hash: hack/verify-helm-chart.sh:42
Warn: pipCommand not pinned by hash: hack/verify-helm-chart.sh:61
Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10
Warn: goCommand not pinned by hash: .github/workflows/linux.yaml:47
Info: 0 out of 17 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 5 third-party GitHubAction dependencies pinned
Info: 2 out of 4 goCommand dependencies pinned
Info: 0 out of 2 downloadThenRun dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 3 containerImage dependencies pinned