feat(df): add maven proxy matcher

Adds the Maven proxy matcher on top of the core proxy model (its target branch, df-mr-04-proxy). Split out of the combined matchers MR so each ecosystem is reviewed on its own.

mavenmatch.go recognizes Maven artifact downloads and uploads against a public Maven upstream (repo.maven.apache.org and mirrors), keyed off the .../<group/path>/<artifact>/<version>/<artifact>-<version>.<ext> path shape. It:

  • targets the primary artifacts (.jar, .pom, .aar, .war) and lets checksum/signature sidecars pass through;
  • matches timestamped snapshot artifacts (for example slf4j-api-1.0-20240101.123456-1.jar under 1.0-SNAPSHOT/) so snapshot downloads are policy-checked rather than bypassing the firewall.

It touches no other ecosystem's files and implements the Matcher interface introduced in the proxy-core MR.

Part of the dependency-firewall breakup. One of three per-ecosystem matcher MRs (pypi, maven, gem), each independent and stacked on df-mr-04-proxy.

Testing

  • make build
  • go test ./internal/dependencyfirewall/proxy/...
  • go vet and gofmt clean.

Merge request reports

Loading
Loading