Info: Possibly incomplete results: error parsing shell code: invalid parameter name: integration/client-cli/admin-cli/src/main/bin/kcadm.sh:0
Info: Possibly incomplete results: error parsing shell code: invalid parameter name: integration/client-cli/admin-cli/src/main/bin/kcreg.sh:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/aurora-delete.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/aurora-delete.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:289: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:335: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:387: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:829: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:864: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:237: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:423: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:454: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:989: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1002: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1027: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1085: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:151: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:192: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:682: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:908: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:950: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1122: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:470: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:509: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:606: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:649: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:762: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:796: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:1069: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:136: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/codeql-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:78: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/documentation.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/documentation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/guides.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/guides.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/guides.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/guides.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/guides.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/guides.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:89: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:186: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:225: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:234: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:260: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:269: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:288: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/js-ci.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/js-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/label.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/label.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:86: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:127: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:137: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:174: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:183: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:197: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:258: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-ci.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/operator-ci.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quarkus-next.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/quarkus-next.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snyk-analysis.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/snyk-analysis.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/snyk-analysis.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/snyk-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snyk-analysis.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/snyk-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snyk-analysis.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/snyk-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy-analysis.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/trivy-analysis.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy-analysis.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/trivy-analysis.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy-analysis.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/keycloak/keycloak/trivy-analysis.yml/main?enable=pin
Warn: containerImage not pinned by hash: operator/Dockerfile:1
Warn: containerImage not pinned by hash: operator/Dockerfile:6: pin your Docker image by updating registry.access.redhat.com/ubi9-micro to registry.access.redhat.com/ubi9-micro@sha256:414cfa255ea10eaef4528a26d5618eb67cf487b635ee20f8f14b9317bfd6a4be
Warn: containerImage not pinned by hash: operator/scripts/Dockerfile-custom-image:3
Warn: containerImage not pinned by hash: quarkus/container/Dockerfile:1
Warn: containerImage not pinned by hash: quarkus/container/Dockerfile:22: pin your Docker image by updating registry.access.redhat.com/ubi9-micro to registry.access.redhat.com/ubi9-micro@sha256:414cfa255ea10eaef4528a26d5618eb67cf487b635ee20f8f14b9317bfd6a4be
Warn: pipCommand not pinned by hash: .github/scripts/ansible/aws_ec2.sh:16
Info: 0 out of 81 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 5 containerImage dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned