Info: Possibly incomplete results: error parsing shell code: statements must be separated by &, ; or a newline: .github/workflows/sca.yml:118
Info: Possibly incomplete results: error parsing shell code: statements must be separated by &, ; or a newline: .github/workflows/sca.yml:158
Info: Possibly incomplete results: error parsing shell code: & can only immediately follow a statement: .github/workflows/sca.yml:40
Info: Possibly incomplete results: error parsing shell code: statements must be separated by &, ; or a newline: .github/workflows/sca.yml:79
Info: Possibly incomplete results: error parsing shell code: statements must be separated by &, ; or a newline: .github/workflows/windows.yml:38
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/cffconvert.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/cffconvert.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/cffconvert.yml:17: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/cffconvert.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:40: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:57: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:71: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/codeql.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/codeql.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/gradle-wrapper-validation.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/gradle-wrapper-validation.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/gradle-wrapper-validation.yml:14: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/gradle-wrapper-validation.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/labeler.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/labeler.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:44: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:51: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:80: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:91: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:107: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:131: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/lint.yml:132: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/lint.yml:135: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/lint.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux_training.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux_training.yml:25: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux_training.yml:35: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/linux_training.yml:42: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/linux_training.yml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/linux_training.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:76: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:92: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:115: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:116: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/mac.yml:121: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/mac.yml:169: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:207: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:217: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/mac.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/mac.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr_checks.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/pr_checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/pr_checks.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/pr_checks.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr_checks.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/pr_checks.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/pr_checks.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/pr_checks.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-c-apidocs.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-c-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-c-apidocs.yml:48: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-c-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-csharp-apidocs.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-csharp-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-csharp-apidocs.yml:59: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-csharp-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-java-apidocs.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-java-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-java-apidocs.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-java-apidocs.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/publish-java-apidocs.yml:33: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-java-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-java-apidocs.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-java-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-js-apidocs.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-js-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-js-apidocs.yml:28: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-js-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-js-apidocs.yml:46: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-js-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-objectivec-apidocs.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-objectivec-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-objectivec-apidocs.yml:47: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-objectivec-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-python-apidocs.yml:27: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-python-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/publish-python-apidocs.yml:52: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/publish-python-apidocs.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:23: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:26: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:31: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:54: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:66: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:69: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:74: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:93: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:108: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:113: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:133: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:145: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:148: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:153: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/sca.yml:173: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/sca.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/stale.yml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/stale.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/title-only-labeler.yml:13: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/title-only-labeler.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows.yml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows.yml:24: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows.yml:29: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows.yml:49: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows.yml/main?enable=pin
Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/windows.yml:50: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows.yml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows.yml/main?enable=pin
Warn: third-party GitHubAction not pinned by hash: .github/workflows/windows.yml:105: update your workflow using https://app.stepsecurity.io/secureworkflow/microsoft/onnxruntime/windows.yml/main?enable=pin
Warn: containerImage not pinned by hash: .devcontainer/Dockerfile:8
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.cuda:12
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.cuda:62
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.jetson:10
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.migraphx:8: pin your Docker image by updating rocm/pytorch:rocm6.2.3_ubuntu22.04_py3.10_pytorch_release_2.3.0 to rocm/pytorch:rocm6.2.3_ubuntu22.04_py3.10_pytorch_release_2.3.0@sha256:54422bee895f9e44bc5257ab03011aae532c5b7cfa39dda00a3000c46db81239
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.openvino:10
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.openvino:42
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.rocm:8: pin your Docker image by updating rocm/pytorch:rocm6.2.3_ubuntu22.04_py3.10_pytorch_release_2.3.0 to rocm/pytorch:rocm6.2.3_ubuntu22.04_py3.10_pytorch_release_2.3.0@sha256:54422bee895f9e44bc5257ab03011aae532c5b7cfa39dda00a3000c46db81239
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.source:7: pin your Docker image by updating mcr.microsoft.com/cbl-mariner/base/python:3 to mcr.microsoft.com/cbl-mariner/base/python:3@sha256:32f8cea198c24589d451c27dd83aee89beb72e34391dfb1e980f69976cfbd6e5
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.source:18: pin your Docker image by updating mcr.microsoft.com/cbl-mariner/base/python:3 to mcr.microsoft.com/cbl-mariner/base/python:3@sha256:32f8cea198c24589d451c27dd83aee89beb72e34391dfb1e980f69976cfbd6e5
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.tensorrt:9
Warn: containerImage not pinned by hash: dockerfiles/Dockerfile.vitisai:7: pin your Docker image by updating xilinx/vitis-ai-cpu:1.3.598 to xilinx/vitis-ai-cpu:1.3.598@sha256:cb502f96f071126f0efc90ee36df90cd0dba5b285891aca05c91dd0d91a74a09
Warn: containerImage not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:3: pin your Docker image by updating rocm/pytorch:rocm4.3.1_ubuntu18.04_py3.6_pytorch_1.9.0 to rocm/pytorch:rocm4.3.1_ubuntu18.04_py3.6_pytorch_1.9.0@sha256:7742f1f1df2eaa58f1e183b9a3ceb7b151f782ab7e9df2a72c69927a48f84aee
Warn: containerImage not pinned by hash: tools/android_custom_build/Dockerfile:7: pin your Docker image by updating ubuntu:20.04 to ubuntu:20.04@sha256:8e5c4f0285ecbb4ead070431d29b576a530d3166df73ec44affc1cd27555141b
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_cpu:1
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_cuda:7
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:19
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:90
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:95
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:103
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:119
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:124
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:129
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:134
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:138
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:143
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.manylinux2_28_rocm:158
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda11_8_tensorrt8_6:10
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda11_8_tensorrt8_6:41
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0:10
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0:49
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:10
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:52
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2004_gpu:11
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2004_gpu:57
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_ffmpeg:11
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_ffmpeg:61
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_opencv:11
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_opencv:59
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_8_tensorrt8_6:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_8_tensorrt8_6:48
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:64
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_3_tensorrt8_6:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_3_tensorrt8_6:51
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:64
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_openvino:2
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:8
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:57
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/aarch64/default/cpu/Dockerfile:5
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/aarch64/python/cpu/Dockerfile:1
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/default/cpu/Dockerfile:5
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/default/cuda11/Dockerfile:5
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/default/cuda12/Dockerfile:5
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/python/cpu/Dockerfile:1
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/inference/x86_64/python/cuda/Dockerfile:7
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/migraphx-ci-pipeline-env.Dockerfile:2: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:0e5e4a57c2499249aafc3b40fcd541e9a456aab7296681a3994d631587203f97
Warn: containerImage not pinned by hash: tools/ci_build/github/linux/docker/rocm-ci-pipeline-env.Dockerfile:2: pin your Docker image by updating ubuntu:22.04 to ubuntu:22.04@sha256:0e5e4a57c2499249aafc3b40fcd541e9a456aab7296681a3994d631587203f97
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.cuda:47-59
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.cuda:47-59
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.cuda:93-104
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.jetson:29
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.jetson:30
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.jetson:31
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.migraphx:21-26
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.openvino:27
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.openvino:29
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.source:21
Warn: pipCommand not pinned by hash: dockerfiles/Dockerfile.source:21
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:52
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:55-58
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:113
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:120-135
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:137
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:139
Warn: pipCommand not pinned by hash: orttraining/tools/amdgpu/Dockerfile.rocm4.3.1.pytorch:140
Warn: pipCommand not pinned by hash: tools/android_custom_build/Dockerfile:45
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda11_8_tensorrt8_6:26
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda11_8_tensorrt8_6:27
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0:17
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0:18
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:17
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:18
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubi8_cuda_tensorrt10_0_torch:49
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2004_gpu:28
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_ffmpeg:28
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.package_ubuntu_2204_gpu_opencv:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_8_tensorrt8_6:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_8_tensorrt8_6:31
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_8_tensorrt8_6:93
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:31
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda11_tensorrt10:109
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_3_tensorrt8_6:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_3_tensorrt8_6:31
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_3_tensorrt8_6:96
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:31
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_cuda12_tensorrt10:109
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:30
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:31
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/Dockerfile.ubuntu_tensorrt_bin:103
Warn: downloadThenRun not pinned by hash: tools/ci_build/github/linux/docker/migraphx-ci-pipeline-env.Dockerfile:62-66
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/migraphx-ci-pipeline-env.Dockerfile:83
Warn: downloadThenRun not pinned by hash: tools/ci_build/github/linux/docker/rocm-ci-pipeline-env.Dockerfile:61-65
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/rocm-ci-pipeline-env.Dockerfile:82-88
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/docker/rocm-ci-pipeline-env.Dockerfile:94-100
Warn: nugetCommand not pinned by hash: csharp/test/Microsoft.ML.OnnxRuntime.EndToEndTests/runtest.sh:29: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: downloadThenRun not pinned by hash: dockerfiles/scripts/install_common_deps.sh:14
Warn: pipCommand not pinned by hash: dockerfiles/scripts/install_common_deps.sh:18
Warn: pipCommand not pinned by hash: dockerfiles/scripts/install_common_deps.sh:19
Warn: pipCommand not pinned by hash: dockerfiles/scripts/install_common_deps.sh:20
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/tensorrt/perf/mem_test/run.sh:119
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/tensorrt/perf/perf.sh:56
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/tensorrt/perf/perf.sh:57
Warn: downloadThenRun not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:42
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:64
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:65
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:70
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:71
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:81
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:187
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:198
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/models/sam2/benchmark_sam2.sh:209
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/run_benchmark.sh:94
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/run_benchmark.sh:96
Warn: pipCommand not pinned by hash: onnxruntime/python/tools/transformers/run_benchmark.sh:98
Warn: downloadThenRun not pinned by hash: tools/ci_build/github/linux/docker/scripts/install_rust.sh:5
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/ort_minimal/build_full_ort_and_create_ort_files.sh:34
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/ort_minimal/nnapi_minimal_build_minimal_ort_and_run_tests.sh:16
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/run_python_tests.sh:45
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/run_python_tests.sh:47
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/run_python_tests.sh:49
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/run_python_tests.sh:52
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/test_custom_ops_pytorch_export.sh:3
Warn: pipCommand not pinned by hash: tools/ci_build/github/linux/test_custom_ops_pytorch_export.sh:5
Warn: pipCommand not pinned by hash: tools/scripts/python_test.sh:15
Warn: pipCommand not pinned by hash: tools/scripts/python_test.sh:20
Warn: pipCommand not pinned by hash: .github/workflows/lint.yml:62
Warn: pipCommand not pinned by hash: .github/workflows/lint.yml:63
Warn: pipCommand not pinned by hash: .github/workflows/lint.yml:98
Warn: pipCommand not pinned by hash: .github/workflows/linux_training.yml:23
Warn: pipCommand not pinned by hash: .github/workflows/pr_checks.yml:44
Warn: pipCommand not pinned by hash: .github/workflows/pr_checks.yml:45
Warn: nugetCommand not pinned by hash: .github/workflows/publish-csharp-apidocs.yml:38: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: nugetCommand not pinned by hash: .github/workflows/publish-csharp-apidocs.yml:39: pin your dependecies by either enabling central package management (https://learn.microsoft.com/nuget/consume-packages/Central-Package-Management) or using a lockfile (https://learn.microsoft.com/nuget/consume-packages/package-references-in-project-files#locking-dependencies)
Warn: pipCommand not pinned by hash: .github/workflows/publish-python-apidocs.yml:35
Warn: pipCommand not pinned by hash: .github/workflows/publish-python-apidocs.yml:37
Warn: pipCommand not pinned by hash: .github/workflows/publish-python-apidocs.yml:38
Info: 0 out of 67 GitHub-owned GitHubAction dependencies pinned
Info: 0 out of 15 third-party GitHubAction dependencies pinned
Info: 8 out of 91 pipCommand dependencies pinned
Info: 0 out of 5 downloadThenRun dependencies pinned
Info: 0 out of 3 nugetCommand dependencies pinned
Info: 2 out of 2 npmCommand dependencies pinned
Info: 0 out of 60 containerImage dependencies pinned