Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:55: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:79: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:311: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:323: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:332: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:356: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:371: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:378: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:395: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:405: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:414: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:430: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:437: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:446: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:522: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:529: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:538: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:549: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:141: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:157: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:190: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:197: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:217: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:229: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:238: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:272: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:287: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:294: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:475: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:482: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:491: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:510: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/bk-ci.yml:512: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-ci.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-streamstorage-python.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-streamstorage-python.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-streamstorage-python.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-streamstorage-python.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-streamstorage-python.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-streamstorage-python.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bk-streamstorage-python.yml:70: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bk-streamstorage-python.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bot.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bot.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/bot.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/bot.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/codeql.yml/master?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/codeql.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:67: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:77: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:83: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:95: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/codeql.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/dead-link-checker.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/dead-link-checker.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/java21-daily-build.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/java21-daily-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/java21-daily-build.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/java21-daily-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/java21-daily-build.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/java21-daily-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/owasp-daily-build.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/owasp-daily-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/owasp-daily-build.yml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/owasp-daily-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/website-deploy.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/website-deploy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/website-deploy.yaml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/website-deploy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/website-deploy.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/website-deploy.yaml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/website-pr-validation.yml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/website-pr-validation.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/website-pr-validation.yml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/website-pr-validation.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/website-pr-validation.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/website-pr-validation.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows-daily-build.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/windows-daily-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows-daily-build.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/windows-daily-build.yml/master?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows-daily-build.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/apache/bookkeeper/windows-daily-build.yml/master?enable=pin
Warn: containerImage not pinned by hash: dev/docker/Dockerfile:20: pin your Docker image by updating maven:3.9.0-eclipse-temurin-11 to maven:3.9.0-eclipse-temurin-11@sha256:612cbee100fa902cc2907c888323db2eb17cc6dc53d78de86920076ebe270775
Warn: containerImage not pinned by hash: dev/release/Dockerfile:20: pin your Docker image by updating maven:3.9.0-eclipse-temurin-8 to maven:3.9.0-eclipse-temurin-8@sha256:a02151d1006f667f2a3d6f752749a4c74cdcb63bd1f5ffd5d1b2a647bf90903d
Warn: containerImage not pinned by hash: docker/Dockerfile:20
Warn: containerImage not pinned by hash: docker/Dockerfile:53
Warn: containerImage not pinned by hash: docker/Dockerfile:67: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:01a3ee0b5e413cefaaffc6abe68c9c37879ae3cced56a8e088b1649e5b269eee
Warn: containerImage not pinned by hash: stream/clients/python/docker/Dockerfile:20: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:01a3ee0b5e413cefaaffc6abe68c9c37879ae3cced56a8e088b1649e5b269eee
Warn: containerImage not pinned by hash: tests/docker-images/all-released-versions-image/Dockerfile:20: pin your Docker image by updating eclipse-temurin:8-jdk-jammy to eclipse-temurin:8-jdk-jammy@sha256:d852f567085d2e50c12526fccd4c51b6503eb9f82b2c521b6c6053339f951abd
Warn: containerImage not pinned by hash: tests/docker-images/all-versions-image/Dockerfile:19: pin your Docker image by updating apachebookkeeper/bookkeeper-all-released-versions:latest to apachebookkeeper/bookkeeper-all-released-versions:latest@sha256:587593cc9693ebdadf95d1c3ec5d1d311fff64408f83e48ec4b89b8be6726745
Warn: containerImage not pinned by hash: tests/docker-images/current-version-image/Dockerfile:20: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:01a3ee0b5e413cefaaffc6abe68c9c37879ae3cced56a8e088b1649e5b269eee
Warn: containerImage not pinned by hash: tests/docker-images/statestore-image/Dockerfile:20: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:01a3ee0b5e413cefaaffc6abe68c9c37879ae3cced56a8e088b1649e5b269eee
Warn: pipCommand not pinned by hash: docker/Dockerfile:84-97
Warn: pipCommand not pinned by hash: stream/clients/python/docker/Dockerfile:34-52
Warn: pipCommand not pinned by hash: tests/docker-images/current-version-image/Dockerfile:37-56
Warn: pipCommand not pinned by hash: tests/docker-images/statestore-image/Dockerfile:33-53
Warn: pipCommand not pinned by hash: stream/clients/python/scripts/publish.sh:26
Warn: pipCommand not pinned by hash: stream/clients/python/scripts/publish_staging.sh:26
Warn: pipCommand not pinned by hash: stream/clients/python/scripts/run_integration_tests.sh:30
Warn: pipCommand not pinned by hash: tests/docker-images/current-version-image/scripts/install-python-client.sh:24
Warn: npmCommand not pinned by hash: .github/workflows/dead-link-checker.yaml:40
Warn: npmCommand not pinned by hash: .github/workflows/website-deploy.yaml:57
Warn: npmCommand not pinned by hash: .github/workflows/website-pr-validation.yml:54
Info: 0 out of 57 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 6 third-party GitHubAction dependencies pinned
Info: 0 out of 8 pipCommand dependencies pinned
Info: 0 out of 3 npmCommand dependencies pinned
Info: 0 out of 10 containerImage dependencies pinned