⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/component_tests.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/component_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/component_tests.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/component_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e_tests.yaml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/e2e_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e_tests.yaml:39: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/e2e_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e_tests.yaml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/e2e_tests.yaml/main?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e_tests.yaml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/e2e_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/e2e_tests.yaml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/e2e_tests.yaml/main?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/e2e_tests.yaml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/e2e_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/olm_tests.yaml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/olm_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/olm_tests.yaml:38: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/olm_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/olm_tests.yaml:45: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/olm_tests.yaml/main?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/olm_tests.yaml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/olm_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/olm_tests.yaml:167: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/olm_tests.yaml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-image.yml:20: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/operator-image.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/operator-image.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/operator-image.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/precommit.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/precommit.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/precommit.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/precommit.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/precommit.yml:32: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/precommit.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/project-codeflare-release.yml:190: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/project-codeflare-release.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tag-and-build.yml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/tag-and-build.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tag-and-build.yml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/tag-and-build.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/tag-and-build.yml:82: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/tag-and-build.yml/main?enable=pin
⚠️
Warn: third-party GitHubAction not pinned by hash: .github/workflows/tag-and-build.yml:146: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/tag-and-build.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit_tests.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/unit_tests.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit_tests.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/unit_tests.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/unit_tests.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/unit_tests.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/update-release-matrix-to-confluence.yml:30: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/update-release-matrix-to-confluence.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify_generated_files.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/verify_generated_files.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify_generated_files.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/verify_generated_files.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify_generated_files.yml:34: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/verify_generated_files.yml/main?enable=pin
⚠️
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/verify_generated_files.yml:36: update your workflow using https://app.stepsecurity.io/secureworkflow/project-codeflare/codeflare-operator/verify_generated_files.yml/main?enable=pin
⚠️
Warn: containerImage not pinned by hash: Dockerfile:2
⚠️
Warn: containerImage not pinned by hash: Dockerfile:21: pin your Docker image by updating registry.access.redhat.com/ubi9/ubi-minimal:latest to registry.access.redhat.com/ubi9/ubi-minimal:latest@sha256:8d905a93f1392d4a8f7fb906bd49bf540290674b28d82de3536bb4d0898bf9d7
ℹ️
Info: 0 out of 27 GitHub-owned GitHubAction dependencies pinned
ℹ️
Info: 0 out of 4 third-party GitHubAction dependencies pinned
ℹ️
Info: 0 out of 2 containerImage dependencies pinned