Loading
feat(df): add pypi proxy matcher
Adds the PyPI proxy matcher on top of the core proxy model (its target branch, df-mr-04-proxy).
Previously this MR carried all three ecosystem matchers; it has been split so each ecosystem is reviewed on its own. This MR is now PyPI-only; maven and gem are separate MRs (see below).
pypimatch.go recognizes:
- PyPI artifact downloads (wheels/sdists served under
/packages/...); - the PEP 658
.whl.metadatasidecar; - twine uploads, extracting the coordinate from the peeked upload body (an over-limit body fails closed).
The end-to-end proxy test that drives a block through the real PyPIMatcher (proxy_pypi_test.go) lives here alongside the matcher it exercises. This MR touches no other ecosystem's files and implements the Matcher interface introduced in the proxy-core MR.
Part of the dependency-firewall breakup. One of three per-ecosystem matcher MRs, each independent and stacked on df-mr-04-proxy:
- this MR — pypi
- df-mr-04c-maven — maven
- df-mr-04d-gem — gem
Testing
make buildgo test ./internal/dependencyfirewall/proxy/...(includes the end-to-end MITM proxy PyPI block test over real TLS)go vetandgofmtclean.
Edited by Michael Eddington