feat(df): add pypi proxy matcher

Adds the PyPI proxy matcher on top of the core proxy model (its target branch, df-mr-04-proxy).

Previously this MR carried all three ecosystem matchers; it has been split so each ecosystem is reviewed on its own. This MR is now PyPI-only; maven and gem are separate MRs (see below).

pypimatch.go recognizes:

  • PyPI artifact downloads (wheels/sdists served under /packages/...);
  • the PEP 658 .whl.metadata sidecar;
  • twine uploads, extracting the coordinate from the peeked upload body (an over-limit body fails closed).

The end-to-end proxy test that drives a block through the real PyPIMatcher (proxy_pypi_test.go) lives here alongside the matcher it exercises. This MR touches no other ecosystem's files and implements the Matcher interface introduced in the proxy-core MR.

Part of the dependency-firewall breakup. One of three per-ecosystem matcher MRs, each independent and stacked on df-mr-04-proxy:

  • this MR — pypi
  • df-mr-04c-maven — maven
  • df-mr-04d-gem — gem

Testing

  • make build
  • go test ./internal/dependencyfirewall/proxy/... (includes the end-to-end MITM proxy PyPI block test over real TLS)
  • go vet and gofmt clean.
Edited by Michael Eddington

Merge request reports

Loading
Loading