@github-advanced-security[bot] commented on this pull request.
In [.github/workflows/assign-copilot-budget.yaml](https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fxebia%2Fenterprise-management%2Fpull%2F49%23discussion_r4090868247&data=05%7C02%7Cjesse.houwing%40xebia.com%7C1ace47fbb69346f8908608df1a0a9dd2%7C3d4d17ea1ae44705947e51369c5a5f79%7C0%7C0%7C639258305082776006%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=p3AXpl3SlDSidKk1xzQazKHv7IxoIKO03A1fk5VrzTE%3D&reserved=0):
> with:
fetch-depth: 0
- name: Azure CLI Login
- uses: azure/login@f5d393ae46f8fde4be8b75f32e3fc50e654ad0ca #v3.0.1
+ uses: azure/login@v3.1.0
CodeQL / Unpinned tag for a non-immutable Action or reusable workflow
Unpinned 3rd party Action 'Assign Copilot Budgets' step [Uses Step](https://eur01.safelinks.protection.outlook.com/?url=http%3A%2F%2F0.0.0.1%2F&data=05%7C02%7Cjesse.houwing%40xebia.com%7C1ace47fbb69346f8908608df1a0a9dd2%7C3d4d17ea1ae44705947e51369c5a5f79%7C0%7C0%7C639258305082810852%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=syG45yYcF905LUBfT7bwQ2iqVwfhaVi9uE%2Bsltt0Fpg%3D&reserved=0) uses 'azure/login' with ref 'v3.1.0', not a pinned commit hash
[Show more details](https://eur01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fxebia%2Fenterprise-management%2Fsecurity%2Fcode-scanning%2F5&data=05%7C02%7Cjesse.houwing%40xebia.com%7C1ace47fbb69346f8908608df1a0a9dd2%7C3d4d17ea1ae44705947e51369c5a5f79%7C0%7C0%7C639258305082829170%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=hup6cNNz3rT81D9UXJDkRkxSvNuy2OEEbJIC6QMswgc%3D&reserved=0)