feat(df): add package command to check a single PURL

Adds glab dependency-firewall package <purl>, a standalone check that evaluates a single package coordinate against the Dependency Firewall policy for the current project and reports the outcome (allow, warning, blocked). No package manager binary is required — it parses a PURL, calls the policy checker directly, and renders the shared summary.

Exit codes: 0 allow/warning, 1 misconfiguration or transport error, 3 blocked. Marked MCP-safe.

Adapted from the umbrella branch for current main:

  • Import bumped client-go v2 → v3 (matching main).
  • Supported PURL types trimmed to what main's purl.Parse accepts: npm, pypi, maven, gem (dropped nuget/cargo/golang references in help, examples, and the ecosystem switch; those land with their ecosystem MRs).
  • Fake-mode tests set GITLAB_CI="" in the shared helper so they honor the GLAB_DF_FAKE_* seam even when the suite runs in CI (matching the pm-layer test convention).

Targets main directly.

Testing

  • go build ./...
  • GITLAB_CI=true go test ./internal/commands/df/... — invalid PURL, unsupported type, allow, warning, and blocked (exit 3, incl. PyPI PEP 503 name normalization).
  • gofmt and golangci-lint clean.
  • make gen-docs generated the package doc page.

Merge request reports

Loading
Loading