feat(df): add pypi wrapper commands behind the firewall proxy

Adds the PyPI-family wrapper subcommands, making pip, uv, twine, pipenv, and poetry usable end-to-end behind the firewall proxy.

Each is a thin dfcmd.NewProxyCmd wrapper: it forwards all arguments verbatim to the underlying binary while routing traffic through the local Dependency Firewall inspection proxy, checking every package download and upload against the project's policy.

Stacked on !3837 (merged) (the dfcmd helper + npm) — review/merge that first. It also depends on the PyPI pm implementations in !3818 (merged); this branch carries the !3818 (merged) pm layer until both merge, after which it rebases down to just the pypi subcommands and their df.go wiring.

The net-new for this MR is the five internal/commands/df/{pip,uv,twine,pipenv,poetry} wrappers and their registration.

Testing

  • go build ./...
  • GITLAB_CI=true go test ./internal/commands/df/... ./internal/dependencyfirewall/pm/...
  • gofmt and golangci-lint clean.
  • make gen-docs regenerated the pip/uv/twine/pipenv/poetry doc pages.

Merge request reports

Loading
Loading