Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/auto-label.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/auto-label.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart-sync.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/chart-sync.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart-sync.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/chart-sync.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github_pagerduty_score_calculation.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/github_pagerduty_score_calculation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/github_pagerduty_score_calculation.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/github_pagerduty_score_calculation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/helm-chart-lint.yaml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/helm-chart-lint.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/multiarch_new.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/multiarch_new.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/multiarch_new.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/multiarch_new.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pager-duty-issue-escalate.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/pager-duty-issue-escalate.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr-issue-validator.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/pr-issue-validator.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sync.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/sync.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/sync.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/devtron-labs/devtron/sync.yml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1
Warn: containerImage not pinned by hash: DockerfileEA:1
Warn: containerImage not pinned by hash: sample-docker-templates/django/Dockerfile:2: pin your Docker image by updating python:3.13-slim to python:3.13-slim@sha256:6544e0e002b40ae0f59bc3618b07c1e48064c4faed3a15ae2fbd2e8f663e8283
Warn: containerImage not pinned by hash: sample-docker-templates/flask/Dockerfile:2: pin your Docker image by updating python:3.13-slim to python:3.13-slim@sha256:6544e0e002b40ae0f59bc3618b07c1e48064c4faed3a15ae2fbd2e8f663e8283
Warn: containerImage not pinned by hash: sample-docker-templates/go/Dockerfile:4
Warn: containerImage not pinned by hash: sample-docker-templates/go/Dockerfile:22: pin your Docker image by updating alpine:3.20 to alpine:3.20@sha256:de4fe7064d8f98419ea6b49190df1abbf43450c1702eeb864fe9ced453c1cc5f
Warn: containerImage not pinned by hash: sample-docker-templates/java/Gradle_Dockerfile:4
Warn: containerImage not pinned by hash: sample-docker-templates/java/Gradle_Dockerfile:17: pin your Docker image by updating eclipse-temurin:21-jdk-jammy to eclipse-temurin:21-jdk-jammy@sha256:e54c6d8517960d3f4abf697a44829af7ead08ccb60d5d309bceedc73b007c2e3
Warn: containerImage not pinned by hash: sample-docker-templates/java/Maven_Dockerfile:4
Warn: containerImage not pinned by hash: sample-docker-templates/java/Maven_Dockerfile:24: pin your Docker image by updating eclipse-temurin:21-jdk-jammy to eclipse-temurin:21-jdk-jammy@sha256:e54c6d8517960d3f4abf697a44829af7ead08ccb60d5d309bceedc73b007c2e3
Warn: containerImage not pinned by hash: sample-docker-templates/kotlin/Dockerfile:2
Warn: containerImage not pinned by hash: sample-docker-templates/kotlin/Dockerfile:20: pin your Docker image by updating eclipse-temurin:21-jre-jammy to eclipse-temurin:21-jre-jammy@sha256:10e079d1384769b34c4f0d3ad8142073ac97230a467f2f08e206b01c0f17c014
Warn: containerImage not pinned by hash: sample-docker-templates/node/Dockerfile:2: pin your Docker image by updating node:22-alpine to node:22-alpine@sha256:10962e8568729b0cfd506170c5a2d1918a2c10ac08c0e6900180b4bac061adc9
Warn: containerImage not pinned by hash: sample-docker-templates/php/Apache_Dockerfile:2: pin your Docker image by updating php:8.3-apache to php:8.3-apache@sha256:e58062dec53ca426816c364824191f7f5881ee3c43d16ada7bd1da6072225cac
Warn: containerImage not pinned by hash: sample-docker-templates/php/Nginx_Dockerfile:2: pin your Docker image by updating ubuntu:24.04 to ubuntu:24.04@sha256:440dcf6a5640b2ae5c77724e68787a906afb8ddee98bf86db94eea8528c2c076
Warn: containerImage not pinned by hash: sample-docker-templates/php/php7.4/Dockerfile:1: pin your Docker image by updating ubuntu:24.04 to ubuntu:24.04@sha256:440dcf6a5640b2ae5c77724e68787a906afb8ddee98bf86db94eea8528c2c076
Warn: containerImage not pinned by hash: sample-docker-templates/react/Dockerfile:4
Warn: containerImage not pinned by hash: sample-docker-templates/react/Dockerfile:29: pin your Docker image by updating nginx:stable-alpine to nginx:stable-alpine@sha256:aed99734248e851764f1f2146835ecad42b5f994081fa6631cc5d79240891ec9
Warn: containerImage not pinned by hash: sample-docker-templates/rust/Dockerfile:2
Warn: containerImage not pinned by hash: sample-docker-templates/rust/Dockerfile:13: pin your Docker image by updating alpine:3.21 to alpine:3.21@sha256:a8560b36e8b8210634f77d9f7f9efd7ffa463e380b75e2e74aff4511df3ef88c
Warn: goCommand not pinned by hash: Dockerfile:3-6
Warn: goCommand not pinned by hash: DockerfileEA:3-6
Warn: pipCommand not pinned by hash: sample-docker-templates/django/Dockerfile:20-23
Warn: pipCommand not pinned by hash: sample-docker-templates/flask/Dockerfile:13-17
Warn: npmCommand not pinned by hash: sample-docker-templates/node/Dockerfile:18-19
Warn: npmCommand not pinned by hash: sample-docker-templates/node/Dockerfile:18-19
Warn: npmCommand not pinned by hash: sample-docker-templates/react/Dockerfile:17
Warn: downloadThenRun not pinned by hash: tests/integrationTesting/create-test-env.sh:22
Warn: downloadThenRun not pinned by hash: tests/integrationTesting/create-test-env.sh:63
Warn: goCommand not pinned by hash: vendor/github.com/go-git/go-git/v5/oss-fuzz.sh:20
Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10
Warn: pipCommand not pinned by hash: .github/workflows/create-release.yml:115
Warn: goCommand not pinned by hash: .github/workflows/enterprise-repo-sync.yaml:41
Warn: pipCommand not pinned by hash: .github/workflows/multiarch_new.yaml:25
Warn: downloadThenRun not pinned by hash: .github/workflows/pr-issue-validator.yaml:45
Info: 0 out of 10 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 4 pipCommand dependencies pinned
Info: 0 out of 3 npmCommand dependencies pinned
Info: 0 out of 3 downloadThenRun dependencies pinned
Info: 2 out of 22 containerImage dependencies pinned
Info: 0 out of 5 goCommand dependencies pinned