import { type PlanResult } from "../internals/execute.js"; import { type Plan, type PlanContext } from "../internals/plan.js"; import { type TrustSource } from "../trust/fetch.js"; import type { AcceptanceTuple } from "./acceptance.js"; import type { BaselineCatalog } from "./catalog.js"; import { type ResolveOrgBaselineEvidenceResult, resolveOrgBaselineEvidence } from "./org.js"; import type { BaselineEvidenceLock } from "./schema.js"; import type { BaselineAuthorization, BaselineHeldComponent } from "./verify.js"; export interface BaselineEvidencePipelineInput { catalog: BaselineCatalog; source: TrustSource; componentIds: readonly string[]; allowPartial?: boolean; /** When set, only accepted-with-conditions decisions for this exact tuple apply. */ acceptanceTuple?: AcceptanceTuple; /** * `held` rides alongside `authorizations` because a caller that reports WHY a * requested component did not install needs the evidence state that held it * back, and re-deriving it downstream would be a second verification whose * verdict could differ from the one this gate acted on. */ buildInstallPlan: (sourceRoot: string, authorizations: readonly BaselineAuthorization[], held: readonly BaselineHeldComponent[]) => Plan | Promise; } export interface BaselineEvidencePipelineDeps { vendorLock?: BaselineEvidenceLock; vendorLockSha256?: string; resolveOrgEvidence?: (input: Parameters[0]) => Promise; } /** Acquire, authorize, re-hash, then and only then construct baseline install actions. */ export declare function executeBaselineEvidencePipeline(ctx: PlanContext, input: BaselineEvidencePipelineInput, deps?: BaselineEvidencePipelineDeps): Promise;