import { z } from "zod"; /** * Evidence-bundle index (`evidence.json`) at the root of a built evidence * ARTIFACT — a typed, kind-tagged catalog of the governance artifacts aih * ALREADY emits (approval locks, skill cards, vet evidence, run logs, reports), * never new evidence of its own. `aih evidence build` packages the on-disk * artifacts into the exact fleet-bundle layout (`files/` copies + * `manifest.json` + `SHA256SUMS`, so `aih verify-bundle` re-checks it * unchanged) and adds this index so an auditor can ask "which of these files is * the skills lock?" without knowing aih's path conventions. The index only * lists what exists — an absent kind is silently absent, never an error. */ /** Index filename inside the bundle (sibling of `manifest.json` / `SHA256SUMS`). */ export declare const EVIDENCE_FILE = "evidence.json"; /** Default output directory for `evidence build` (gitignored `.aih/`). */ export declare const DEFAULT_EVIDENCE_OUT = ".aih/evidence-bundle"; /** Canonical source directory for separately versioned, typed Strix evidence. */ export declare const STRIX_SECURITY_EVIDENCE_DIR = ".aih/security/strix"; /** The closed set of artifact kinds aih emits today (all schemaVersion 1 on disk). */ export declare const EVIDENCE_KINDS: readonly ["run-log", "baseline-evidence", "skill-evidence", "skill-card", "skills-lock", "trust-lock", "packs", "report", "sarif", "strix-security-evidence", "truth-pack"]; export declare const EvidenceKindSchema: z.ZodEnum<{ "baseline-evidence": "baseline-evidence"; packs: "packs"; report: "report"; "run-log": "run-log"; sarif: "sarif"; "skill-card": "skill-card"; "skill-evidence": "skill-evidence"; "skills-lock": "skills-lock"; "strix-security-evidence": "strix-security-evidence"; "trust-lock": "trust-lock"; "truth-pack": "truth-pack"; }>; export type EvidenceKind = z.infer; /** * One indexed artifact: its kind, the repo-relative source path (equal to the * manifest's `files[].path`, so `files/` is the packaged copy), the * sha256 of the exact packaged bytes, and the artifact's OWN declared * schemaVersion (read from its JSON when it carries one, else 1). Paths reuse * the marketplace's rel-path refinement — a hosted, hand-editable index must * never steer a consumer's filesystem reads out of the bundle. */ export declare const EvidenceArtifactSchema: z.ZodObject<{ kind: z.ZodEnum<{ "baseline-evidence": "baseline-evidence"; packs: "packs"; report: "report"; "run-log": "run-log"; sarif: "sarif"; "skill-card": "skill-card"; "skill-evidence": "skill-evidence"; "skills-lock": "skills-lock"; "strix-security-evidence": "strix-security-evidence"; "trust-lock": "trust-lock"; "truth-pack": "truth-pack"; }>; path: z.ZodString; sha256: z.ZodString; schemaVersion: z.ZodNumber; }, z.core.$strict>; export declare const EvidenceHarnessSchema: z.ZodObject<{ aihVersion: z.ZodString; releaseTag: z.ZodString; releaseCommit: z.ZodString; packageName: z.ZodString; tarballSha256: z.ZodString; checksumFile: z.ZodString; cosignBundle: z.ZodString; npmProvenance: z.ZodEnum<{ "not-checked": "not-checked"; unknown: "unknown"; unverified: "unverified"; verified: "verified"; }>; verificationCommand: z.ZodString; }, z.core.$strict>; export declare const EvidenceBundleSchema: z.ZodObject<{ schemaVersion: z.ZodLiteral<1>; artifacts: z.ZodArray; path: z.ZodString; sha256: z.ZodString; schemaVersion: z.ZodNumber; }, z.core.$strict>>; harness: z.ZodOptional; verificationCommand: z.ZodString; }, z.core.$strict>>; }, z.core.$strict>; export type EvidenceArtifact = z.infer; export type EvidenceHarness = z.infer; export type EvidenceBundle = z.infer;