import { type CiscoShardManifest, type CiscoShardResult, type JoinedCiscoShardEvidence } from "../trust/cisco-shards.js"; import { scanTrustTreeWithAnalyzers, type TrustScanResult } from "../trust/scan.js"; import type { BaselineCatalog, BaselineCatalogComponent } from "./catalog.js"; import { type BaselineEvidenceLock, type BaselineSourceEvidence } from "./schema.js"; type ScanTrustTreeOptions = NonNullable[1]>; export interface BaselineComponentScanInput { sourceRoot: string; component: BaselineCatalogComponent; } export type BaselineComponentScanner = (input: BaselineComponentScanInput) => Promise; export type BaselineTreeScanner = (root: string, options?: ScanTrustTreeOptions) => Promise; export interface VetBaselineCatalogOptions { scanComponent?: BaselineComponentScanner; scanTree?: BaselineTreeScanner; scanOptions?: ScanTrustTreeOptions; analyzerVersions?: Readonly>; requiredAnalyzers?: readonly string[] | ((component: BaselineCatalogComponent, sourceRoot: string) => readonly string[]); requiredDetectorsForComponent?: (component: BaselineCatalogComponent, sourceRoot: string) => NonNullable; /** Per-occurrence evidence side channel; never folded into vendor-lock aggregation. */ onComponentScan?: (component: BaselineCatalogComponent, scan: TrustScanResult) => void; /** Capture one complete source ledger and deterministically project it into components. */ sourceWideScan?: boolean; onSourceWideScan?: (scan: TrustScanResult) => void; /** Prior lock to splice unchanged, identity-matched receipts from (Decision 1/4). * Absent ⟹ every component is treated as new and fully scanned. */ reuseFrom?: BaselineEvidenceLock; /** Disable reuse outright and rescan every component (Decision 5's escape * hatch and the migration tool) — takes priority over `reuseFrom`. */ full?: boolean; /** * Scan every Cisco skill input once under one exact-source manifest, then * project the validated SARIF into component scans. A dispatcher may execute * disjoint shards on remote vets; without one, exactly one local shard is * allowed so a single host is never accidentally oversubscribed. */ sourceWideCisco?: { analyzerLockSha256: string; shardCount?: number; profile?: string; workerConcurrency?: number; dispatch?: (manifest: CiscoShardManifest) => Promise; }; } export declare function defaultComponentScanner(scanOptions: ScanTrustTreeOptions, scanTree: BaselineTreeScanner, requiredDetectorsForComponent?: VetBaselineCatalogOptions["requiredDetectorsForComponent"], sharedCiscoEvidence?: JoinedCiscoShardEvidence): BaselineComponentScanner; export declare function vetBaselineCatalog(sourceRoot: string, catalog: BaselineCatalog, options?: VetBaselineCatalogOptions): Promise; export {};