rusty-fez 0.4.0

Agent-native management CLI for Fedora/RHEL (drives cockpit-bridge)
Documentation
name: codeql

on:
  push:
    branches:
      - main
  pull_request:
    branches:
      - main
  schedule:
    # Weekly catch for advisories landing against unchanged code.
    - cron: "27 4 * * 1"

permissions:
  contents: read

jobs:
  analyze:
    name: analyze
    runs-on: ubuntu-latest
    permissions:
      security-events: write
      contents: read
    steps:
      - name: Checkout repository
        uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10  # v6.0.3
        with:
          persist-credentials: false
      - name: Initialize CodeQL
        uses: github/codeql-action/init@8aad20d150bbac5944a9f9d289da16a4b0d87c1e  # v4.36.2
        with:
          languages: rust
          # Rust's CodeQL extractor only supports buildless ("none") extraction;
          # "manual"/"autobuild" are rejected at init time.
          build-mode: none
      - name: Perform CodeQL analysis
        uses: github/codeql-action/analyze@8aad20d150bbac5944a9f9d289da16a4b0d87c1e  # v4.36.2
        with:
          category: "/language:rust"