feat(df): add pm runner + env-proxy engine (npm)
Adds the package-manager runner that powers glab df run, plus npm/pnpm as the reference manager so the shared run flow is exercised end to end.
The engine (pm.go) routes a manager's HTTPS traffic through the inspection proxy, injects trust for the proxy's MITM CA, forwards args verbatim, propagates the child's exit code, and handles signal/context cancellation with deferred CA-bundle cleanup. Managers no longer rewrite their own config; they implement a small PackageManager interface: proxy env vars (Environment), CA-trust env vars (CATrustEnviron), and the ecosystem coordinate matcher (Matcher).
npm and pnpm ship here as the reference implementation. The remaining ecosystems' managers (PyPI, RubyGems, yarn) follow in a stacked MR.
This is the first half of the split of the former pm-core MR (was ~700 additive lines) into a reviewable engine MR and a thin managers MR.
Testing
go build ./...go test -race ./internal/dependencyfirewall/pm/...(run flow: proxy/CA env, exit-code propagation, interrupt/context-cancel + temp-file cleanup, env dedup)go vetandgofmtclean.