import type { Runner } from "../internals/proc.js"; import type { Platform } from "../platform/base.js"; import { CISCO_MCP_SCANNER_PROJECT, CISCO_MCP_SCANNER_VERSION, CISCO_SKILL_SCANNER_PROJECT, CISCO_SKILL_SCANNER_VERSION, SEMGREP_PROJECT, SEMGREP_VERSION, SNYK_AGENT_SCAN_PROJECT, SNYK_AGENT_SCAN_VERSION, type TrustDetectorName } from "../trust/detectors.js"; import { type SkillSpectorImageApproval } from "../trust/images.js"; import type { BaselineCatalogComponent } from "./catalog.js"; import type { VetBaselineCatalogOptions } from "./vet.js"; export { CISCO_MCP_SCANNER_PROJECT, CISCO_MCP_SCANNER_VERSION, CISCO_SKILL_SCANNER_PROJECT, CISCO_SKILL_SCANNER_VERSION, SEMGREP_PROJECT, SEMGREP_VERSION, SNYK_AGENT_SCAN_PROJECT, SNYK_AGENT_SCAN_VERSION, }; export declare const CISCO_SKILL_SCANNER_SPEC = "cisco-ai-skill-scanner==2.0.13"; export declare const CISCO_SKILL_SCANNER_LOCK: string; export declare const CISCO_MCP_SCANNER_LOCK: string; export declare const SEMGREP_LOCK: string; export declare const SNYK_AGENT_SCAN_LOCK: string; export declare function ciscoSkillScannerLockSha256(): string; export declare const REQUIRED_BASELINE_DETECTORS: readonly ["skillspector", "semgrep", "cisco"]; export declare const REQUIRED_BASELINE_ANALYZERS: readonly ["aih-native", "skillspector@docker", "semgrep@uv:1.173.0", "cisco@uvx"]; export declare function requiredBaselineAnalyzersForComponent(component: Pick, sourceRoot?: string): readonly string[]; export declare function requiredBaselineDetectorsForComponent(component: Pick, sourceRoot?: string): readonly TrustDetectorName[]; export declare function baselineAnalyzerVersions(): Readonly>; export declare function requiredBaselineVetOptions(runtime: { run: Runner; platform: Platform; env: NodeJS.ProcessEnv; progress?: (message: string) => void; }): VetBaselineCatalogOptions; export interface BaselinePreflightRuntime { run: Runner; platform: Platform; env: NodeJS.ProcessEnv; skillspectorImageApprovals?: readonly SkillSpectorImageApproval[]; } /** * Fail fast, before a multi-minute vet, when a REQUIRED baseline analyzer is not * actually runnable in this environment (for example, an offline uv cache that no * longer resolves the pinned Cisco skill-scanner). This preserves fail-closed — * an unprovisioned required analyzer still blocks — while replacing the opaque * mid-vet "missing required baseline analyzers" abort with an actionable * provisioning error. It never fabricates a receipt, skips an analyzer, or lowers * the required-analyzer floor. */ export declare function preflightRequiredBaselineAnalyzers(runtime: BaselinePreflightRuntime): Promise;