Remove the if-wrapper that was swallowing the exit code. The step now
fails naturally when stop exits 1, which is the correct CI behavior —
a blocked package should fail the job.
pmg proxy stop now waits for the proxy process to exit, reads the final
blocked count written to the state file on shutdown, and exits non-zero
when one or more packages were blocked during the session.
This gives CI a clear failure signal from the proxy itself, separate
from the package manager's own exit code.
Adds pmg proxy command group for running a long-lived MITM proxy that
intercepts all package manager traffic without requiring PMG shims or
wrappers. Targets CI/CD pipelines where env vars can be set globally.
- pmg proxy start: starts proxy with npm+pypi interceptors, writes
state file (pid/addr/ca-cert-path), auto-blocks suspicious packages
- pmg proxy stop: sends SIGTERM to the running proxy
- pmg proxy env: emits HTTP_PROXY/HTTPS_PROXY/SSL_CERT_FILE etc. as
shell exports, or writes directly to $GITHUB_ENV with --gha
- pmg proxy status: shows running/stopped status
GHA usage:
pmg proxy start &
pmg proxy env --gha # populates env for all subsequent steps
npm install # intercepted automatically, no wrapper needed
Also adds .github/workflows/persistent-proxy-e2e.yml to validate the
persistent proxy mode end-to-end in CI.