feat(df): add npm wrapper command behind the firewall proxy

Adds the user-facing glab dependency-firewall npm command, making the npm package manager usable end-to-end behind the firewall proxy.

Introduces the dfcmd wrapper helper (dfcmd.NewProxyCmd) that every package-manager subcommand will reuse. A wrapper forwards all arguments verbatim to the package-manager binary (DisableFlagParsing) while routing its traffic through the local Dependency Firewall inspection proxy. The project is resolved from the git remote, so the wrappers deliberately do not advertise --repo (TestNoRepoOverriteAdvertised enforces this).

npm's matcher and pm implementation already landed on main; this MR wires them to a command. It is the first of the ecosystem "slices" — each later slice (pypi, ruby, maven, …) adds its own subcommand on top of this dfcmd helper.

Testing

  • go build ./...
  • GITLAB_CI=true go test ./internal/commands/df/... (wrapper arg forwarding, proxy env, subcommand registration, no --repo advertised)
  • gofmt and golangci-lint clean.
  • make gen-docs regenerated the npm doc page.

Merge request reports

Loading
Loading