Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:168: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:171: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:175: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:177: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:100: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:104: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:129: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:155: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-testing.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/chart-testing.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-testing.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/chart-testing.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-testing.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/chart-testing.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-testing.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/chart-testing.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-testing.yaml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/chart-testing.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-testing.yaml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/chart-testing.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-testing.yaml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/chart-testing.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-testing.yaml:87: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/chart-testing.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/private-registries.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/private-registries.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/private-registries.yaml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/private-registries.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/private-registries.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/private-registries.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/private-registries.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/private-registries.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/private-registries.yaml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/private-registries.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-docs.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/publish-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-docs.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/publish-docs.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-helm-chart.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/publish-helm-chart.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-helm-chart.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/publish-helm-chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-helm-chart.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/publish-helm-chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-helm-chart.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/publish-helm-chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-helm-chart.yaml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/publish-helm-chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-snapshot.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release-snapshot.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-snapshot.yaml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release-snapshot.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-snapshot.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release-snapshot.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release-snapshot.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release-snapshot.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-snapshot.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release-snapshot.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-snapshot.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release-snapshot.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-snapshot.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release-snapshot.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release-snapshot.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release-snapshot.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:94: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:120: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:127: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/release.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/title_checker-labeler.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/title_checker-labeler.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/title_checker-labeler.yaml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/title_checker-labeler.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/validate-chart-appVersion.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/validate-chart-appVersion.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/validate-chart-appVersion.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/aquasecurity/trivy-operator/validate-chart-appVersion.yaml/main?enable=pin
Warn: containerImage not pinned by hash: build/mkdocs-material/Dockerfile:1: pin your Docker image by updating squidfunk/mkdocs-material:8.2.7 to squidfunk/mkdocs-material:8.2.7@sha256:63b7eefc788ee83928a75d32f10493a347e63a00d569d26ed0ebf98df9c44f63
Warn: containerImage not pinned by hash: build/trivy-operator/Dockerfile:1: pin your Docker image by updating alpine:3.20.6 to alpine:3.20.6@sha256:de4fe7064d8f98419ea6b49190df1abbf43450c1702eeb864fe9ced453c1cc5f
Warn: containerImage not pinned by hash: build/trivy-operator/Dockerfile.ubi8:1: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal:8.5 to registry.access.redhat.com/ubi8/ubi-minimal:8.5@sha256:3f32ebba0cbf3849a48372d4fc3a4ce70816f248d39eb50da7ea5f15c7f9d120
Warn: pipCommand not pinned by hash: build/mkdocs-material/Dockerfile:3
Warn: pipCommand not pinned by hash: build/mkdocs-material/Dockerfile:4
Warn: pipCommand not pinned by hash: .github/workflows/publish-docs.yaml:43
Warn: pipCommand not pinned by hash: .github/workflows/publish-docs.yaml:44
Warn: pipCommand not pinned by hash: .github/workflows/publish-docs.yaml:45
Info: 1 out of 29 GitHub-owned GitHubAction dependencies pinned
Info: 3 out of 50 third-party GitHubAction dependencies pinned
Info: 0 out of 3 containerImage dependencies pinned
Info: 0 out of 5 pipCommand dependencies pinned