Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/govulncheck.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/govulncheck.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:98: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:183: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:207: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:103: update your workflow using https://app.stepsecurity.io/secureworkflow/CrunchyData/postgres-operator/trivy.yaml/main?enable=pin
Warn: containerImage not pinned by hash: build/postgres-operator/Dockerfile:1: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal to registry.access.redhat.com/ubi8/ubi-minimal@sha256:b2a1bec3dfbc7a14a1d84d98934dfe8fdde6eb822a211286601cf109cbccb075
Info: 0 out of 28 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 2 third-party GitHubAction dependencies pinned
Info: 0 out of 1 containerImage dependencies pinned