Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/codeql-analysis.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-crd.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/generate-crd.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate-crd.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/generate-crd.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/generate.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/generate.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/generate.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/generate.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/generate.yml:109: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/generate.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/maven.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/maven.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:102: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/maven.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/maven.yml:147: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/maven.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/release.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/release.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/snapshot.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/snapshot.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/kubernetes-client/java/snapshot.yml/master?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:3
Warn: containerImage not pinned by hash: client-java-contrib/Dockerfile:1: pin your Docker image by updating docker:stable to docker:stable@sha256:fd4d028713fd05a1fb896412805daed82c4a0cc84331d8dad00cb596d7ce3e3a
Warn: containerImage not pinned by hash: examples/examples-release-17/Dockerfile:1: pin your Docker image by updating openjdk:8-jre to openjdk:8-jre@sha256:667a15e7bc533a90fb39ddb7e5bed63162ac3c13a97e6c698bf4f139f51b7d33
Warn: containerImage not pinned by hash: examples/examples-release-18/Dockerfile:1: pin your Docker image by updating openjdk:8-jre to openjdk:8-jre@sha256:667a15e7bc533a90fb39ddb7e5bed63162ac3c13a97e6c698bf4f139f51b7d33
Warn: containerImage not pinned by hash: examples/examples-release-19/Dockerfile:1: pin your Docker image by updating openjdk:8-jre to openjdk:8-jre@sha256:667a15e7bc533a90fb39ddb7e5bed63162ac3c13a97e6c698bf4f139f51b7d33
Warn: containerImage not pinned by hash: examples/examples-release-20/Dockerfile:1: pin your Docker image by updating openjdk:8-jre to openjdk:8-jre@sha256:667a15e7bc533a90fb39ddb7e5bed63162ac3c13a97e6c698bf4f139f51b7d33
Warn: containerImage not pinned by hash: examples/examples-release-latest/Dockerfile:1: pin your Docker image by updating openjdk:8-jre to openjdk:8-jre@sha256:667a15e7bc533a90fb39ddb7e5bed63162ac3c13a97e6c698bf4f139f51b7d33
Warn: downloadThenRun not pinned by hash: .devcontainer/library-scripts/node-debian.sh:29
Info: 0 out of 25 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 7 containerImage dependencies pinned
Info: 0 out of 1 downloadThenRun dependencies pinned