In trying to get this action whitelisted for use in my GitHub enterprise, our security team recommends mutable tags (or immutable sha digest tags) be used with Dockerfiles, e.g. https://github.com/todogroup/repolinter/blob/main/Dockerfile#L13
I do realize this may also introduce additional maintenance overhead.