/** * Named risk-gate categories: high-risk change classes that warrant a deliberate * "ask" (never a hard deny) before an agent proceeds. * * Data ported verbatim from LeanHarness `.lh/policies/risk-gates.yml` (MIT, * Copyright (c) 2026 LeanHarness contributors) — every category name, description, * `path_patterns`, `command_patterns`, and the `behavior: ask` invariant are * preserved. The enforcement notes are ported verbatim; the approval-source * precedence is reframed into tool-agnostic prose (the source referenced * LeanHarness-internal `.lh/` paths that do not exist in aih). The aih JSON sidecar * + doc renderers are original. * * Posture: ask-not-deny. aih emits these as a CI-checkable sidecar + human doc, * plus (at enterprise posture) the sidecar's generated consumer — a PR-diff * workflow that surfaces touched gates in the customer's pipeline (#507 slice D). * The consuming CLI (where it has a hook seam) reads the same categories * in-session. aih never gates a live tool call itself. */ /** Version of the ported policy data (tracks the source `risk-gates.yml` version). */ export declare const POLICY_VERSION = "0.1"; export interface RiskGate { name: string; description: string; pathPatterns: string[]; commandPatterns: string[]; /** ask-not-deny: a risk gate prompts for approval, it never refuses outright. */ behavior: "ask"; } /** Ported verbatim from `.lh/policies/risk-gates.yml` (LeanHarness, MIT). */ export declare const RISK_GATES: RiskGate[]; /** * Approval-source precedence (reframed from LeanHarness's `.lh/`-pathed sources * into tool-agnostic prose). A gate's "ask" is satisfied when one of these, in * order, records approval for the touched path/command. */ export declare const APPROVAL_SOURCES: readonly string[]; /** Enforcement notes — ported verbatim from `risk-gates.yml` (LeanHarness, MIT). */ export declare const ENFORCEMENT_NOTES: readonly string[]; export interface RiskGatesJsonOptions { required?: boolean; } /** The CI-checkable JSON sidecar: a CI job can diff a PR's touched paths/commands against this. */ export declare function riskGatesJson(options?: RiskGatesJsonOptions): Record; /** * One gate path pattern against one changed path — a faithful TS mirror of the * generated workflow's bash matcher (`case "$path" in $pattern`), where `*` * matches any run of characters INCLUDING `/` and a leading globstar-slash * prefix may also match zero directories (the workflow retries with that prefix * stripped). Exported so * the consumer's matching POLICY is unit-tested against representative diffs, * not merely asserted as generated strings — the `blockedLicensesFound` pattern * from the SCA gate. Covers the pattern language the gates actually use * (`*`, `?`, literals; no bracket expressions). */ export declare function gatePatternMatches(path: string, pattern: string): boolean; export interface TouchedRiskGate { name: string; /** The changed paths that matched this gate's path patterns, input order kept. */ paths: string[]; } /** * The gates a PR's changed paths would trigger — the same verdict the generated * workflow surfaces as warnings. Path patterns only: command patterns cannot be * derived from a diff and stay with the agent-side consumer. */ export declare function riskGatesTouched(changedPaths: readonly string[], gates?: readonly RiskGate[]): TouchedRiskGate[]; /** * Render `.github/workflows/risk-gates.yml` — the sidecar's generated consumer. * A pull_request job (named after the sidecar's `ci.checkName`) reads * `sidecarPath` with jq, diffs the PR's changed paths against each gate's path * patterns, and surfaces every touched gate as a `::warning::` annotation plus a * job-summary table. Ask-not-deny end to end: a touched gate NEVER fails the * build (`risk-gates` grades warn at every posture) — the human PR review * answers the ask. The only hard failure is a corrupted sidecar; a missing one * is a notice, since committing the sidecar is what opts the repo in. * * This emits a GENERATED FILE only. The harness never runs CI — the workflow * executes in the customer's pipeline, mirroring the SCA workflow boundary. */ export declare function riskGatesWorkflowYaml(sidecarPath: string): string; /** * Human-readable risk-gate reference. Doubles as the "runs in YOUR CI" note (the * gates are checked by the customer's pipeline against `risk-gates.json`, never by * aih), mirroring the existing `ciNote()` boundary in guardrails/index.ts. */ export declare function riskGatesDoc(): string;