Security Advisory: SonarQube Scanner GitHub Action

Yes, @master takes the latest commit, which includes the fix. And, we generally recommend not pinning to master, since there might eventually be a breaking change. I’d reccomend using @5.