Info: Possibly incomplete results: error parsing shell code: invalid parameter name: integration/client-cli/admin-cli/src/main/bin/kcadm.sh:0
Info: Possibly incomplete results: error parsing shell code: invalid parameter name: integration/client-cli/admin-cli/src/main/bin/kcreg.sh:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aurora-delete.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/aurora-delete.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:799: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:998: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1011: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1094: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1131: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:118: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:291: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:337: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:389: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:867: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:425: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:456: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:472: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:511: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:608: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:651: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:832: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:911: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:956: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1036: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:239: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:684: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1078: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:765: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:123: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:96: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/guides.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/guides.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/guides.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/guides.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/guides.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/guides.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:291: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:151: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:156: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:189: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:228: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:237: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:263: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:272: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/label.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/label.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:149: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:163: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:224: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quarkus-next.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/quarkus-next.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snyk-analysis.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/snyk-analysis.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/snyk-analysis.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/snyk-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snyk-analysis.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/snyk-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snyk-analysis.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/snyk-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy-analysis.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/trivy-analysis.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy-analysis.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/trivy-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy-analysis.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/trivy-analysis.yml/main?enable=pin
Warn: containerImage not pinned by hash: operator/Dockerfile:1
Warn: containerImage not pinned by hash: operator/Dockerfile:6: pin your Docker image by updating registry.access.redhat.com/ubi9-micro to registry.access.redhat.com/ubi9-micro@sha256:dca8bc186bb579f36414c6ad28f1dbeda33e5cf0bd5fc1c51430cc578e25f819
Warn: containerImage not pinned by hash: operator/scripts/Dockerfile-custom-image:3
Warn: containerImage not pinned by hash: quarkus/container/Dockerfile:1
Warn: containerImage not pinned by hash: quarkus/container/Dockerfile:22: pin your Docker image by updating registry.access.redhat.com/ubi9-micro to registry.access.redhat.com/ubi9-micro@sha256:dca8bc186bb579f36414c6ad28f1dbeda33e5cf0bd5fc1c51430cc578e25f819
Warn: pipCommand not pinned by hash: .github/scripts/ansible/aws_ec2.sh:16
Info: 0 out of 80 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 5 third-party GitHubAction dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 5 containerImage dependencies pinned