Info: Possibly incomplete results: error parsing shell code: unclosed here-document 'EOT': examples/quickstart/tutorial/hadoop/docker/Dockerfile:76
Info: Possibly incomplete results: error parsing shell code: invalid parameter name: integration-tests/script/copy_resources_template.sh:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/ci.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/ci.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cron-job-its.yml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/cron-job-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cron-job-its.yml:127: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/cron-job-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cron-job-its.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/cron-job-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cron-job-its.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/cron-job-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cron-job-its.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/cron-job-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/distribution-checks.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/distribution-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labeler.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/labeler.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-revised-its.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-revised-its.yml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-revised-its.yml:101: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-revised-its.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-revised-its.yml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-revised-its.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-revised-its.yml:202: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-revised-its.yml:214: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-standard-its.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-standard-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-standard-its.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-standard-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-standard-its.yml:73: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-standard-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-standard-its.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-standard-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/reusable-standard-its.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/reusable-standard-its.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/revised-its.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/revised-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/stale.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/standard-its.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/standard-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/standard-its.yml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/standard-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/standard-its.yml:151: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/standard-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/standard-its.yml:160: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/standard-its.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:152: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:154: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:161: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:194: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/static-checks.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/static-checks.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-and-integration-tests-unified.yml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/unit-and-integration-tests-unified.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-and-integration-tests-unified.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/unit-and-integration-tests-unified.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-and-integration-tests-unified.yml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/unit-and-integration-tests-unified.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-and-integration-tests-unified.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/unit-and-integration-tests-unified.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-and-integration-tests-unified.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/unit-and-integration-tests-unified.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-and-integration-tests-unified.yml:125: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/unit-and-integration-tests-unified.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-and-integration-tests-unified.yml:178: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/unit-and-integration-tests-unified.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/worker.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/worker.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/worker.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/worker.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/worker.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/worker.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/worker.yml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/druid/worker.yml/master?enable=pin
Warn: containerImage not pinned by hash: distribution/docker/Dockerfile:26
Warn: containerImage not pinned by hash: distribution/docker/Dockerfile:52
Warn: containerImage not pinned by hash: distribution/docker/Dockerfile:69
Warn: containerImage not pinned by hash: distribution/docker/Dockerfile:71
Warn: containerImage not pinned by hash: distribution/docker/Dockerfile.mariadb:21
Warn: containerImage not pinned by hash: distribution/docker/Dockerfile.mysql:21
Warn: containerImage not pinned by hash: distribution/docker/DockerfileBuildTarAdvanced:22
Warn: containerImage not pinned by hash: examples/quickstart/jupyter-notebooks/Dockerfile:28: pin your Docker image by updating jupyter/base-notebook to jupyter/base-notebook@sha256:8c903974902b0e9d45d9823c2234411de0614c5c98c4bb782b3d4f55b3e435e6
Warn: containerImage not pinned by hash: examples/quickstart/tutorial/hadoop/docker/Dockerfile:18: pin your Docker image by updating centos:7 to centos:7@sha256:be65f488b7764ad3638f236b7b515b3678369a5124c47b8d32916d6487418ea4
Warn: containerImage not pinned by hash: integration-tests-ex/image/docker/Dockerfile:37
Warn: containerImage not pinned by hash: integration-tests/docker/Dockerfile:17
Warn: containerImage not pinned by hash: integration-tests/docker/Dockerfile:31
Warn: pipCommand not pinned by hash: examples/quickstart/jupyter-notebooks/Dockerfile:34-41
Warn: pipCommand not pinned by hash: examples/quickstart/jupyter-notebooks/Dockerfile:48
Warn: npmCommand not pinned by hash: .github/scripts/create-jacoco-coverage-report.sh:50
Warn: pipCommand not pinned by hash: .github/scripts/setup_generate_license.sh:25
Warn: pipCommand not pinned by hash: .github/scripts/setup_generate_license.sh:26
Warn: npmCommand not pinned by hash: dev/update-version-master:40
Warn: downloadThenRun not pinned by hash: integration-tests/script/setup_k8s_cluster.sh:25
Warn: npmCommand not pinned by hash: .github/workflows/static-checks.yml:167
Info: 0 out of 49 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 4 third-party GitHubAction dependencies pinned
Info: 0 out of 12 containerImage dependencies pinned
Info: 0 out of 4 pipCommand dependencies pinned
Info: 0 out of 3 npmCommand dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned