Loading
feat(df): add maven proxy matcher
Adds the Maven proxy matcher on top of the core proxy model (its target branch, df-mr-04-proxy). Split out of the combined matchers MR so each ecosystem is reviewed on its own.
mavenmatch.go recognizes Maven artifact downloads and uploads against a public Maven upstream (repo.maven.apache.org and mirrors), keyed off the .../<group/path>/<artifact>/<version>/<artifact>-<version>.<ext> path shape. It:
- targets the primary artifacts (
.jar,.pom,.aar,.war) and lets checksum/signature sidecars pass through; - matches timestamped snapshot artifacts (for example
slf4j-api-1.0-20240101.123456-1.jarunder1.0-SNAPSHOT/) so snapshot downloads are policy-checked rather than bypassing the firewall.
It touches no other ecosystem's files and implements the Matcher interface introduced in the proxy-core MR.
Part of the dependency-firewall breakup. One of three per-ecosystem matcher MRs (pypi, maven, gem), each independent and stacked on df-mr-04-proxy.
Testing
make buildgo test ./internal/dependencyfirewall/proxy/...go vetandgofmtclean.