Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/build.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/build.yaml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:166: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:174: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/build.yaml:181: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/build.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coherence-matrix.yaml:142: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/coherence-matrix.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/coherence-matrix.yaml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/coherence-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coherence-matrix.yaml:180: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/coherence-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coherence-matrix.yaml:188: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/coherence-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coherence-matrix.yaml:244: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/coherence-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compatibility-tests.yaml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/compatibility-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/compatibility-tests.yaml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/compatibility-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compatibility-tests.yaml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/compatibility-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compatibility-tests.yaml:124: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/compatibility-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/compatibility-tests.yaml:174: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/compatibility-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/doc-check.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/doc-check.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/doc-check.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/doc-check.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/doc-check.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/doc-check.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/doc-check.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/doc-check.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/istio-tests.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/istio-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/istio-tests.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/istio-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/istio-tests.yaml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/istio-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/istio-tests.yaml:90: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/istio-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/istio-tests.yaml:134: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/istio-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/k3d-tests.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k3d-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/k3d-tests.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k3d-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/k3d-tests.yaml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k3d-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/k3d-tests.yaml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k3d-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/k3d-tests.yaml:112: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k3d-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/k8s-matrix.yaml:81: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k8s-matrix.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/k8s-matrix.yaml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k8s-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/k8s-matrix.yaml:114: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k8s-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/k8s-matrix.yaml:122: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k8s-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/k8s-matrix.yaml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/k8s-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minikube-matrix.yaml:58: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/minikube-matrix.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/minikube-matrix.yaml:85: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/minikube-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minikube-matrix.yaml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/minikube-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minikube-matrix.yaml:99: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/minikube-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/minikube-matrix.yaml:130: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/minikube-matrix.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prometheus-tests.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/prometheus-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/prometheus-tests.yaml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/prometheus-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prometheus-tests.yaml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/prometheus-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prometheus-tests.yaml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/prometheus-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/prometheus-tests.yaml:117: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/prometheus-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tanzu-tests.yaml:43: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/tanzu-tests.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tanzu-tests.yaml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/tanzu-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tanzu-tests.yaml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/tanzu-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tanzu-tests.yaml:84: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/tanzu-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tanzu-tests.yaml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/tanzu-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tanzu-tests.yaml:139: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/tanzu-tests.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/trivy.yaml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trivy.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/trivy.yaml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trivy.yaml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/oracle/coherence-operator/trivy.yaml/main?enable=pin
Warn: containerImage not pinned by hash: Dockerfile:7
Warn: containerImage not pinned by hash: debug/Base.Dockerfile:7
Warn: containerImage not pinned by hash: debug/Dockerfile:6
Warn: containerImage not pinned by hash: examples/016_simple_docker_image/src/docker/Dockerfile:6: pin your Docker image by updating gcr.io/distroless/java11-debian11 to gcr.io/distroless/java11-debian11@sha256:56ffee16297ae1d3484bd47575cacd8102e5ba2be425a7772b3f8ad0d48def3b
Warn: containerImage not pinned by hash: examples/025_extend_client/src/docker/Dockerfile:6: pin your Docker image by updating gcr.io/distroless/java11-debian11 to gcr.io/distroless/java11-debian11@sha256:56ffee16297ae1d3484bd47575cacd8102e5ba2be425a7772b3f8ad0d48def3b
Warn: containerImage not pinned by hash: examples/910_polyglot_demo/go/Dockerfile:8
Warn: containerImage not pinned by hash: examples/910_polyglot_demo/js/Dockerfile:8: pin your Docker image by updating node:18-alpine to node:18-alpine@sha256:8d6421d663b4c28fd3ebc498332f249011d118945588d0a35cb9bc4b8ca09d9e
Warn: containerImage not pinned by hash: examples/910_polyglot_demo/py/Dockerfile:8: pin your Docker image by updating python:3.11-slim to python:3.11-slim@sha256:139020233cc412efe4c8135b0efe1c7569dc8b28ddd88bddb109b764f8977e30
Warn: containerImage not pinned by hash: examples/no-operator/04_istio/Dockerfile:1
Warn: containerImage not pinned by hash: examples/no-operator/04_istio/Dockerfile:3: pin your Docker image by updating container-registry.oracle.com/middleware/coherence-ce:14.1.2-0-1 to container-registry.oracle.com/middleware/coherence-ce:14.1.2-0-1@sha256:340fe318c807782feb5d0033631910c0a12b7f4d928a37410f850f0b6c33b50d
Warn: containerImage not pinned by hash: java/operator-compatibility/src/main/resources/Dockerfile:1
Warn: containerImage not pinned by hash: java/operator-compatibility/src/main/resources/Dockerfile:8
Warn: containerImage not pinned by hash: java/operator-test-spring-2/src/main/docker/Dir.Dockerfile:1: pin your Docker image by updating gcr.io/distroless/java17-debian12 to gcr.io/distroless/java17-debian12@sha256:eba3112cc48f46e4eac153191f229baa7bd1895f9d6219b497699b803fd4b4a2
Warn: containerImage not pinned by hash: java/operator-test-spring-2/src/main/docker/FatJar.Dockerfile:1: pin your Docker image by updating gcr.io/distroless/java17-debian12 to gcr.io/distroless/java17-debian12@sha256:eba3112cc48f46e4eac153191f229baa7bd1895f9d6219b497699b803fd4b4a2
Warn: containerImage not pinned by hash: java/operator-test-spring/src/main/docker/Dir.Dockerfile:1: pin your Docker image by updating gcr.io/distroless/java17-debian12 to gcr.io/distroless/java17-debian12@sha256:eba3112cc48f46e4eac153191f229baa7bd1895f9d6219b497699b803fd4b4a2
Warn: containerImage not pinned by hash: java/operator-test-spring/src/main/docker/FatJar.Dockerfile:1: pin your Docker image by updating gcr.io/distroless/java17-debian12 to gcr.io/distroless/java17-debian12@sha256:eba3112cc48f46e4eac153191f229baa7bd1895f9d6219b497699b803fd4b4a2
Warn: containerImage not pinned by hash: tekton/builder.Dockerfile:1: pin your Docker image by updating container-registry.oracle.com/os/oraclelinux:9 to container-registry.oracle.com/os/oraclelinux:9@sha256:da8e17b69334e4cf9f9f853d1a6309795aad8e0cfb4b0721f7e822e8dd729d87
Warn: goCommand not pinned by hash: debug/Base.Dockerfile:12
Warn: npmCommand not pinned by hash: examples/910_polyglot_demo/js/Dockerfile:19
Warn: pipCommand not pinned by hash: examples/910_polyglot_demo/py/Dockerfile:16
Warn: goCommand not pinned by hash: hack/golang/govulncheck.sh:12
Warn: downloadThenRun not pinned by hash: hack/istio/get-istio-latest.sh:28
Warn: downloadThenRun not pinned by hash: hack/tanzu/get-tanzu.sh:51
Info: 0 out of 46 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 11 third-party GitHubAction dependencies pinned
Info: 0 out of 2 goCommand dependencies pinned
Info: 0 out of 1 npmCommand dependencies pinned
Info: 0 out of 1 pipCommand dependencies pinned
Info: 0 out of 2 downloadThenRun dependencies pinned
Info: 0 out of 17 containerImage dependencies pinned