feat(df): add pypi, ruby, and yarn env-proxy managers
Adds the remaining PackageManager implementations on top of the pm engine reviewed in !3817 (merged): the PyPI family (pip, pipenv, uv, poetry, twine), the RubyGems family (gem, bundle), and yarn.
Each is a thin implementation of the interface: proxy env vars, CA-trust env vars, and the ecosystem coordinate matcher. yarn.go carries the Yarn Berry fix — Berry (v2+) ignores the standard HTTP(S)_PROXY variables and only honors YARN_HTTP(S)_PROXY, so without them the firewall proxy is silently bypassed (fail-open); the yarn subtest of TestManagerEnvironAndCATrust covers it. pip.go/poetry.go pin PIP_PROXY for the same reason: pip sets session.trust_env = False when it has its own proxy config and then ignores HTTPS_PROXY.
Second half of the pm-core split. Targets df-mr-06a-pm-engine (!3817 (merged)); review/merge that first. The maven/gradle JVM managers and the shared jvmtrust helper are intentionally deferred to a later MR.
Testing
go build ./...go test -race ./internal/dependencyfirewall/pm/...(manager metadata, per-ecosystem matcher types, and the exact proxy-routing/CA-trust env vars each manager emits viaTestManagerEnvironAndCATrust, including the Yarn Berry and pipPIP_PROXYpins)go vetandgofmtclean.