Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/coverity_scan.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/coverity_scan.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/create-tag.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/create-tag.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr_best_practices.yml:15: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/pr_best_practices.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/release.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/stale-cleanup.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/stale-cleanup.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:271: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:272: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:277: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:97: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:110: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:128: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:144: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:196: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:206: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:241: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:305: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tests.yml:308: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:72: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:158: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:164: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:185: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tests.yml:262: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/tests.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trigger-gitlab.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/trigger-gitlab.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-gitlab.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/trigger-gitlab.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/trigger-gitlab.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/trigger-gitlab.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/trigger-gitlab.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/osbuild/osbuild-composer/trigger-gitlab.yml/main?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:1: pin your Docker image by updating fedora:36 to fedora:36@sha256:64cd00a0e2b92d527c0a0954162a73e85f160e3a53c38325b51e87d6aab4e266
Warn: containerImage not pinned by hash: distribution/Dockerfile-config:1: pin your Docker image by updating fedora:40 to fedora:40@sha256:3c86d25fef9d2001712bc3d9b091fc40cf04be4767e48f1aa3b785bf58d300ed
Warn: containerImage not pinned by hash: distribution/Dockerfile-fauxauth:1
Warn: containerImage not pinned by hash: distribution/Dockerfile-fauxauth:9: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal:latest to registry.access.redhat.com/ubi9/ubi-minimal:latest@sha256:92b1d5747a93608b6adb64dfd54515c3c5a360802db4706765ff3d8470df6290
Warn: containerImage not pinned by hash: distribution/Dockerfile-ubi:1
Warn: containerImage not pinned by hash: distribution/Dockerfile-ubi:22
Warn: containerImage not pinned by hash: distribution/Dockerfile-ubi:25: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal:latest to registry.access.redhat.com/ubi9/ubi-minimal:latest@sha256:92b1d5747a93608b6adb64dfd54515c3c5a360802db4706765ff3d8470df6290
Warn: containerImage not pinned by hash: distribution/Dockerfile-ubi-maintenance:1
Warn: containerImage not pinned by hash: distribution/Dockerfile-ubi-maintenance:9: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal:latest to registry.access.redhat.com/ubi9/ubi-minimal:latest@sha256:92b1d5747a93608b6adb64dfd54515c3c5a360802db4706765ff3d8470df6290
Warn: containerImage not pinned by hash: distribution/Dockerfile-ubi-packer:1: pin your Docker image by updating quay.io/app-sre/packer:latest to quay.io/app-sre/packer:latest@sha256:7a11ad98feb15d6b5a09ea815c81d7286c76b9f5cbe93953bfcafc19cca17439
Warn: containerImage not pinned by hash: distribution/Dockerfile-worker:1
Warn: containerImage not pinned by hash: distribution/Dockerfile-worker:14: pin your Docker image by updating fedora to fedora@sha256:ee88ab8a5c8bf78687ddcecadf824767e845adc19d8cdedb56f48521eb162b43
Warn: goCommand not pinned by hash: .devcontainer/Dockerfile:26
Warn: goCommand not pinned by hash: .devcontainer/Dockerfile:27
Warn: goCommand not pinned by hash: .devcontainer/Dockerfile:28
Warn: goCommand not pinned by hash: .devcontainer/Dockerfile:29
Warn: goCommand not pinned by hash: .devcontainer/Dockerfile:30
Warn: goCommand not pinned by hash: distribution/Dockerfile-ubi:23
Warn: goCommand not pinned by hash: test/cases/api.sh:133
Warn: pipCommand not pinned by hash: test/cases/ostree-simplified-installer.sh:28
Warn: pipCommand not pinned by hash: tools/appsre-worker-packer-container.sh:7
Warn: goCommand not pinned by hash: tools/dbtest-prepare-env.sh:5
Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10
Info: 0 out of 19 GitHub-owned GitHubAction dependencies pinned
Info: 1 out of 12 third-party GitHubAction dependencies pinned
Info: 0 out of 12 containerImage dependencies pinned
Info: 3 out of 12 goCommand dependencies pinned
Info: 0 out of 2 pipCommand dependencies pinned