feat(df): add cargo proxy matcher

Adds CargoMatcher, the proxy classifier for the crates ecosystem, as a standalone matcher MR (following the precedent of the merged npm/pypi/gem/maven matcher MRs, each of which landed before its manager/wrapper).

The matcher recognizes:

  • Downloads in two shapes — the legacy registry API path (/api/v1/crates/{crate}/{version}/download) and the sparse-index {crate}-{version}.crate file (default since cargo 1.70). Because the sparse download URL is registry-defined (crates.io vs. Artifactory/Cloudsmith differ), it matches on the .crate filename so it keeps working behind third-party registries.
  • Publishes — PUT /api/v1/crates/new, decoding the length-prefixed frame ([u32 LE json_len][json][u32 LE crate_len][.crate]) to extract name and version.

CargoMatcher is not wired into any manager yet; the df cargo wrapper and pm.Cargo manager that consume it follow in the stacked MR. Targets main directly.

Testing

  • GITLAB_CI=true go test ./internal/dependencyfirewall/proxy/ — table tests cover legacy + sparse downloads, publish frame decoding, and non-matching paths.
  • gofmt and golangci-lint clean.

Merge request reports

Loading
Loading