feat(df): add pypi, ruby, and yarn env-proxy managers

Adds the remaining PackageManager implementations on top of the pm engine reviewed in !3817 (merged): the PyPI family (pip, pipenv, uv, poetry, twine), the RubyGems family (gem, bundle), and yarn.

Each is a thin implementation of the interface: proxy env vars, CA-trust env vars, and the ecosystem coordinate matcher. yarn.go carries the Yarn Berry fix — Berry (v2+) ignores the standard HTTP(S)_PROXY variables and only honors YARN_HTTP(S)_PROXY, so without them the firewall proxy is silently bypassed (fail-open); the yarn subtest of TestManagerEnvironAndCATrust covers it. pip.go/poetry.go pin PIP_PROXY for the same reason: pip sets session.trust_env = False when it has its own proxy config and then ignores HTTPS_PROXY.

Second half of the pm-core split. Targets df-mr-06a-pm-engine (!3817 (merged)); review/merge that first. The maven/gradle JVM managers and the shared jvmtrust helper are intentionally deferred to a later MR.

Testing

  • go build ./...
  • go test -race ./internal/dependencyfirewall/pm/... (manager metadata, per-ecosystem matcher types, and the exact proxy-routing/CA-trust env vars each manager emits via TestManagerEnvironAndCATrust, including the Yarn Berry and pip PIP_PROXY pins)
  • go vet and gofmt clean.
Edited by Michael Eddington

Merge request reports

Loading
Loading