Loading
feat(df): add cargo proxy matcher
Adds CargoMatcher, the proxy classifier for the crates ecosystem, as a standalone matcher MR (following the precedent of the merged npm/pypi/gem/maven matcher MRs, each of which landed before its manager/wrapper).
The matcher recognizes:
- Downloads in two shapes — the legacy registry API path (
/api/v1/crates/{crate}/{version}/download) and the sparse-index{crate}-{version}.cratefile (default since cargo 1.70). Because the sparse download URL is registry-defined (crates.io vs. Artifactory/Cloudsmith differ), it matches on the.cratefilename so it keeps working behind third-party registries. - Publishes —
PUT /api/v1/crates/new, decoding the length-prefixed frame ([u32 LE json_len][json][u32 LE crate_len][.crate]) to extract name and version.
CargoMatcher is not wired into any manager yet; the df cargo wrapper and pm.Cargo manager that consume it follow in the stacked MR. Targets main directly.
Testing
GITLAB_CI=true go test ./internal/dependencyfirewall/proxy/— table tests cover legacy + sparse downloads, publish frame decoding, and non-matching paths.gofmtandgolangci-lintclean.