Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/build.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/build.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-apidiff.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/go-apidiff.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-apidiff.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/go-apidiff.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/go-apidiff.yaml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/go-apidiff.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-verdiff.yaml:10: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/go-verdiff.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:75: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:137: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:146: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sanity.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/sanity.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sanity.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/sanity.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/stale.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/test.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/unit.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/unit.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/unit.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-registry/unit.yaml/master?enable=pin
Warn: containerImage not pinned by hash: configmap-registry.Dockerfile:1
Warn: containerImage not pinned by hash: configmap-registry.Dockerfile:2
Warn: containerImage not pinned by hash: fbc-dir/file-based-catalog.Dockerfile:3: pin your Docker image by updating quay.io/operator-framework/opm:latest to quay.io/operator-framework/opm:latest@sha256:f9ecca9c1fd94862b39877a3da4a020986fa5fcb693fac626e969a7e2640267b
Warn: containerImage not pinned by hash: index.Dockerfile:1
Warn: containerImage not pinned by hash: opm-example.Dockerfile:3: pin your Docker image by updating quay.io/operator-framework/opm:latest to quay.io/operator-framework/opm:latest@sha256:f9ecca9c1fd94862b39877a3da4a020986fa5fcb693fac626e969a7e2640267b
Warn: containerImage not pinned by hash: registry.Dockerfile:1
Warn: containerImage not pinned by hash: release/goreleaser.opm.Dockerfile:5
Warn: containerImage not pinned by hash: release/goreleaser.opm.Dockerfile:6: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:b2141e58dd62baf0ff941e48ee8fdc58ffe4296bbe05b400eff1122484586160
Warn: containerImage not pinned by hash: upstream-builder.Dockerfile:1
Warn: containerImage not pinned by hash: upstream-builder.Dockerfile:12: pin your Docker image by updating alpine:3 to alpine:3@sha256:8a1f59ffb675680d47db6337b49d22281a139e9d709335b492be023728e11715
Warn: containerImage not pinned by hash: upstream-example.Dockerfile:1
Warn: containerImage not pinned by hash: upstream-opm-builder.Dockerfile:6
Warn: containerImage not pinned by hash: upstream-opm-builder.Dockerfile:21: pin your Docker image by updating quay.io/operator-framework/alpine to quay.io/operator-framework/alpine@sha256:be9bdc0ef8e96dbc428dc189b31e2e3b05523d96d12ed627c37aa2936653258c
Warn: goCommand not pinned by hash: .github/workflows/sanity.yaml:23
Info: 0 out of 23 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 4 third-party GitHubAction dependencies pinned
Info: 0 out of 13 containerImage dependencies pinned
Info: 1 out of 2 goCommand dependencies pinned