Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/back-port.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/back-port.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/back-port.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/back-port.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart.yaml:12: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart.yaml:61: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart.yaml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/chart.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart.yaml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/chart.yaml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/chart.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/codeql-analysis.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/codeql-analysis.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql-analysis.yaml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/codeql-analysis.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/commit-lint.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/commit-lint.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/e2e.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e.yaml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e.yaml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/e2e.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/go.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yaml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/go.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yaml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/go.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yaml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/go.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yaml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/go.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/go.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go.yaml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/go.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go.yaml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/go.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue-commands.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/issue-commands.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue-commands.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/issue-commands.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/issue-commands.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/issue-commands.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue-commands.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/issue-commands.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/issue-commands.yml:68: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/issue-commands.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/issue-commands.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/issue-commands.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/post-submit.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/post-submit.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-submit.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/post-submit.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-submit.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/post-submit.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/post-submit.yaml:64: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/post-submit.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/unit-test.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/unit-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-test.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/unit-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-test.yaml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/unit-test.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit-test.yaml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/unit-test.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/unit-test.yaml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/unit-test.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/unit-test.yaml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/kubevela/workflow/unit-test.yaml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:3
Warn: containerImage not pinned by hash: Dockerfile:27
Warn: containerImage not pinned by hash: Dockerfile.e2e:3
Warn: containerImage not pinned by hash: Dockerfile.e2e:27
Info: 0 out of 28 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 22 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 2 out of 2 goCommand dependencies pinned
Info: 1 out of 1 npmCommand dependencies pinned