Per GitHub security recommendations, all (3rd-party) actions should be pinned to a commit hash because these version tags are mutable. Consider adding codeql to this repo. https://github.com/github/codeql/blob/main/actions/ql/src/Security/CWE-829/UnpinnedActionsTag.md _Originally posted by @joebowbeer in [d504c54](https://github.com/microsoft/Windows-driver-samples/commit/d504c54cf595e9185617a3e611e417617be8c0b8#r154501982)_