Loading
feat(df): add package command to check a single PURL
Adds glab dependency-firewall package <purl>, a standalone check that evaluates a single package coordinate against the Dependency Firewall policy for the current project and reports the outcome (allow, warning, blocked). No package manager binary is required — it parses a PURL, calls the policy checker directly, and renders the shared summary.
Exit codes: 0 allow/warning, 1 misconfiguration or transport error, 3 blocked. Marked MCP-safe.
Adapted from the umbrella branch for current main:
- Import bumped
client-gov2 → v3 (matching main). - Supported PURL types trimmed to what main's
purl.Parseaccepts: npm, pypi, maven, gem (dropped nuget/cargo/golang references in help, examples, and the ecosystem switch; those land with their ecosystem MRs). - Fake-mode tests set
GITLAB_CI=""in the shared helper so they honor theGLAB_DF_FAKE_*seam even when the suite runs in CI (matching the pm-layer test convention).
Targets main directly.
Testing
go build ./...GITLAB_CI=true go test ./internal/commands/df/...— invalid PURL, unsupported type, allow, warning, and blocked (exit 3, incl. PyPI PEP 503 name normalization).gofmtandgolangci-lintclean.make gen-docsgenerated the package doc page.