/** * Declared, curated, deliberately OVER-inclusive closure of source roots whose * behavior shapes the `aih-native` trust-scan analyzer's findings (issue #444, * design Decision 2). Over-inclusion is safe: an edit to an unrelated file under * one of these roots just forces an extra (harmless) identity bump and re-vet. * Under-inclusion is the real risk — a native-detector edit outside this closure * would leave the identity, and therefore reuse, unaffected, silently keeping a * stale `pass` receipt alive. * * `src/baseline-evidence/vet.ts` and `src/baseline-evidence/hash.ts` are * deliberately NOT reachable by these roots: they shape receipt production for * every analyzer alike (native, skillspector, cisco), not the aih-native * analyzer specifically. A change there is caught by the full migration re-vet * plus the `baseline:check` byte-diff instead of by this identity (design O1, * resolved: exclude). */ export declare const NATIVE_DETECTOR_GLOB_ROOTS: readonly ["src/trust", "src/secrets", "src/mcp/policy.ts", "src/skill/license.ts", "src/config/posture.ts"]; /** * Live discovery of the declared closure's CURRENT file set. Used only by the * dev-time `check:native-identity` / `baseline:native-identity` gates — never at * scan time, since the shipped npm package has no `src/` tree to read. */ export declare function discoverNativeDetectorSourceFiles(root?: string): string[]; /** * Live digest recompute over the declared closure's current bytes — dev-time * only (see `discoverNativeDetectorSourceFiles`). `sha256(join("\n", sorted( * "\0")))`, sliced to 12 hex characters. */ export declare function computeNativeDetectorDigest(root?: string): string; /** * Committed, generated snapshot of the declared closure (data-only, like * `vendor-lock.json`/`vendor.ts`). Regenerate with * `npm run baseline:native-identity -- --write` whenever `check:native-identity` * reports drift, then review the diff like any other generated artifact. */ export declare const NATIVE_DETECTOR_SOURCES: readonly string[]; export declare const NATIVE_DETECTOR_DIGEST: string; /** * `aih-native`'s analyzer identity: a pure content digest over the declared * native-detector source closure — deliberately NOT a package version (issue * #444). A version prefix would invalidate every receipt at each release version * bump even when no detector source changed, forcing a full re-vet on every * release PR. Reads the committed constant (never re-hashes `src/` at call * time), because the identity must resolve from the shipped `dist/` package too. */ export declare function nativeAnalyzerIdentity(): string;