feat(df): add JVM PKCS#12 truststore helper

Adds the shared jvmtrust helper that the upcoming Maven and Gradle wrapper commands use to make the JVM trust the Dependency Firewall proxy.

The helper builds a PKCS#12 truststore containing the proxy MITM CA (plus any user CAs prepended into the proxy bundle) and the host's system roots, then returns the -Djavax.net.ssl.* system-property flags pointing at it. The JVM then trusts the proxy while still validating public TLS dependencies.

Landing this on its own keeps the Maven/Gradle ecosystem MR focused on the matcher and package managers. Adds the software.sslmate.com/src/go-pkcs12 dependency.

Testing

  • go build ./...
  • GITLAB_CI=true go test ./internal/dependencyfirewall/pm/... — covers truststore generation (proxy CA present), the JVM system-property flags, MAVEN_OPTS preservation, and the empty-bundle path.
  • gofmt and golangci-lint clean.

Merge request reports

Loading
Loading