Info: Possibly incomplete results: error parsing shell code: "foo(" must be followed by ): vendor/sigs.k8s.io/controller-runtime/Makefile:0
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:106: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:140: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:146: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e-tests.yml:189: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/e2e-tests.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/go-verdiff.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/go-verdiff.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/goreleaser.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/goreleaser.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/goreleaser.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/goreleaser.yaml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/goreleaser.yaml:60: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/goreleaser.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/quickstart.yml:11: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/quickstart.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sanity.yaml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/sanity.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sanity.yaml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/sanity.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sanity.yaml:22: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/sanity.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sanity.yaml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/sanity.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sanity.yaml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/sanity.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sanity.yaml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/sanity.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/stale.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/unit.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit.yml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/operator-framework/operator-lifecycle-manager/unit.yml/master?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:1: pin your Docker image by updating gcr.io/distroless/static:debug to gcr.io/distroless/static:debug@sha256:b2141e58dd62baf0ff941e48ee8fdc58ffe4296bbe05b400eff1122484586160
Warn: containerImage not pinned by hash: test/e2e/data/kiali-image-bundle/Dockerfile:3: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal to registry.access.redhat.com/ubi8/ubi-minimal@sha256:b2a1bec3dfbc7a14a1d84d98934dfe8fdde6eb822a211286601cf109cbccb075
Warn: containerImage not pinned by hash: test/e2e/data/kiali-image-registry/Dockerfile:2: pin your Docker image by updating quay.io/operator-framework/operator-registry-server to quay.io/operator-framework/operator-registry-server@sha256:d1d7f6fa945d69de30830cc1b037337dabca9fa51cc6ff7e21286a50ee20ad8b
Warn: containerImage not pinned by hash: test/e2e/skopeo.Dockerfile:1: pin your Docker image by updating fedora:31 to fedora:31@sha256:444773966064dcc3c268d8b496e76dbbbb49d16586d5a969c4082579e6b77616
Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10
Warn: goCommand not pinned by hash: vendor/google.golang.org/grpc/regenerate.sh:35
Warn: goCommand not pinned by hash: vendor/google.golang.org/grpc/vet.sh:37
Info: 0 out of 24 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 4 third-party GitHubAction dependencies pinned
Info: 0 out of 4 containerImage dependencies pinned
Info: 1 out of 4 goCommand dependencies pinned