import type { Posture } from "../config/posture.js"; import type { Check, CheckCode } from "../internals/verify.js"; import { type AcceptanceDecision, type AcceptanceTuple } from "./acceptance.js"; import { type BaselineCatalog } from "./catalog.js"; import type { OrgBaselineEvidence } from "./org.js"; import type { BaselineEvidenceLock } from "./schema.js"; export interface BaselineAuthorization { componentId: string; source: string; pinnedSha: string; treeSha256: string; tier: "vendor" | "org"; issuer: string; evidenceSha256: string; /** Effective disposition. Absent/"pass" = signed vet pass. "accepted-with-conditions" * = the raw vet verdict is BLOCKED (preserved untouched in the lock) and an exact * signed acceptance decision admitted this component (W4 ruling (e)). */ effective?: "pass" | "accepted-with-conditions"; /** Present iff `effective` is "accepted-with-conditions": the signed decision. */ acceptance?: { decisionId: string; recordSha256: string; acceptedFindingCodes: string[]; }; } export interface BaselineHeldComponent { componentId: string; routeCode: CheckCode; codes: string[]; details: string[]; } export interface VerifyBaselineComponentsInput { sourceRoot: string; catalog: BaselineCatalog; componentIds: readonly string[]; posture: Posture; vendorLock: BaselineEvidenceLock; vendorLockSha256: string; orgEvidence?: OrgBaselineEvidence; /** Signed accepted-with-conditions decisions; defaults to the shipped artifact. */ acceptanceDecisions?: readonly AcceptanceDecision[]; /** When set, only decisions matching this exact profile/host/adapter tuple apply. */ acceptanceTuple?: AcceptanceTuple; } export interface BaselineVerificationResult { checks: Check[]; authorizations: BaselineAuthorization[]; held: BaselineHeldComponent[]; } export declare function verifyBaselineComponents(input: VerifyBaselineComponentsInput): BaselineVerificationResult;