/** * Fail closed when the committed baseline evidence no longer describes the pins * this build declares. * * Cheap by construction: it reads the committed lock and compares recorded * identities against declared ones. It does not rescan anything, so it can run * on every event without the cost that made the from-scratch re-vet impractical * to repeat — while still being the thing that decides when that expensive run * is genuinely required. */ export declare function checkBaselinePinCurrency(lockPath: string): { ok: boolean; report: string; }; /** The committed lock this check defends, resolved relative to this module. */ export declare function defaultLockPath(): string; /** * The CLI body, exported and parameterized so its reporting and exit behaviour * are testable directly. Returns the exit code rather than setting it, so a * caller — including a test — observes the decision instead of a side effect. */ export declare function runPinCurrencyCli(lockPath?: string, write?: (text: string) => void): number;