import { z } from "zod"; /** * Policy-bundle envelope — ONE versioned shape shared by the local * `aih-org-policy.json` (embedded whole as `policy`) and a future SIGNED org * bundle an org distributes to its fleet. The envelope adds only provenance * (`bundleVersion`, `issuer`, `issuedAt`) and optional ring metadata around the * existing {@link OrgPolicySchema}; it never forks the policy shape itself, so a * repo validating its local policy and a fleet validating a distributed bundle * are exercising the SAME schema. No network code and no signing live here — * signing rides `SHA256SUMS` like every other aih artifact, and the read-only * gate over both forms is `aih policy validate`. */ /** Deployment-ring metadata a bundle may carry (names only; rollout logic is future work). */ declare const PolicyRingSchema: z.ZodObject<{ name: z.ZodString; description: z.ZodOptional; }, z.core.$strict>; export declare const PolicyBundleSchema: z.ZodObject<{ schemaVersion: z.ZodLiteral<1>; bundleVersion: z.ZodString; issuer: z.ZodString; issuedAt: z.ZodISODateTime; policy: z.ZodObject<{ schemaVersion: z.ZodLiteral<2>; minimumPosture: z.ZodEnum<{ enterprise: "enterprise"; vibe: "vibe"; }>; references: z.ZodObject<{ repoContract: z.ZodString; }, z.core.$strip>; command: z.ZodOptional; }, z.core.$strict>>>; remove: z.ZodDefault>; }, z.core.$strict>>; ask: z.ZodOptional; }, z.core.$strict>>>; remove: z.ZodDefault>; }, z.core.$strict>>; }, z.core.$strict>>; riskGates: z.ZodOptional>; commandPatterns: z.ZodDefault>; }, z.core.$strict>>>; override: z.ZodDefault; pathPatterns: z.ZodOptional>; commandPatterns: z.ZodOptional>; }, z.core.$strict>>>; }, z.core.$strict>>; licenses: z.ZodOptional>>; }, z.core.$strict>>; security: z.ZodOptional; mode: z.ZodEnum<{ deep: "deep"; quick: "quick"; standard: "standard"; }>; maxBudgetCents: z.ZodNumber; maxTurns: z.ZodNumber; timeoutMs: z.ZodNumber; telemetry: z.ZodLiteral<"off">; imageDigest: z.ZodString; allowLiveTargets: z.ZodDefault>; allowMounts: z.ZodDefault>; enabled: z.ZodLiteral; required: z.ZodBoolean; }, z.core.$strict>, z.ZodObject<{ targetKind: z.ZodLiteral<"local-fixture">; mode: z.ZodEnum<{ deep: "deep"; quick: "quick"; standard: "standard"; }>; maxBudgetCents: z.ZodNumber; maxTurns: z.ZodNumber; timeoutMs: z.ZodNumber; telemetry: z.ZodLiteral<"off">; imageDigest: z.ZodString; allowLiveTargets: z.ZodDefault>; allowMounts: z.ZodDefault>; enabled: z.ZodLiteral; required: z.ZodLiteral; }, z.core.$strict>], "enabled">; }, z.core.$strict>>; mcp: z.ZodOptional>; approvals: z.ZodDefault; acceptEgress: z.ZodLiteral; reason: z.ZodString; reviewer: z.ZodOptional; approvedAt: z.ZodString; }, z.core.$strict>>>; allowManagedOnly: z.ZodDefault; incumbentHosts: z.ZodDefault>>>; githubHost: z.ZodOptional>>; disabledServers: z.ZodDefault>; }, z.core.$strict>>; trust: z.ZodOptional; reason: z.ZodOptional; }, z.core.$strict>>>; requireSignedSource: z.ZodDefault; requiredDetectors: z.ZodOptional>>; requiredChecks: z.ZodOptional>; baselineOverrides: z.ZodOptional; owner: z.ZodString; repo: z.ZodString; pinnedSha: z.ZodString; bundle: z.ZodString; signingRepository: z.ZodString; reason: z.ZodString; reviewer: z.ZodString; approvedAt: z.ZodString; }, z.core.$strict>>>; internalScopes: z.ZodDefault>; skillspector: z.ZodOptional; approvedAt: z.ZodString; }, z.core.$strict>>>; }, z.core.$strict>>; }, z.core.$strict>>; capabilityPackages: z.ZodOptional; repository: z.ZodString; }, z.core.$strict>; roots: z.ZodArray; }, z.core.$strict>>; governance: z.ZodOptional>; }, z.core.$strict>, z.ZodObject<{ policyVersion: z.ZodString; catalog: z.ZodObject<{ reviewed: z.ZodDefault; description: z.ZodString; capabilities: z.ZodDefault>; risks: z.ZodDefault>; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; targets: z.ZodArray>; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; lifecycle: z.ZodEnum<{ deprecated: "deprecated"; retired: "retired"; supported: "supported"; }>; evidence: z.ZodObject<{ record: z.ZodString; }, z.core.$strict>; findings: z.ZodDefault>>; autoExecute: z.ZodDefault; framework: z.ZodOptional>; clarification: z.ZodOptional; annotation: z.ZodOptional; }, z.core.$strict>>>; custom: z.ZodDefault; description: z.ZodString; capabilities: z.ZodDefault>; risks: z.ZodDefault>; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; targets: z.ZodArray>; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; lifecycle: z.ZodEnum<{ deprecated: "deprecated"; retired: "retired"; supported: "supported"; }>; evidence: z.ZodObject<{ record: z.ZodString; }, z.core.$strict>; findings: z.ZodDefault>>; autoExecute: z.ZodDefault; framework: z.ZodOptional>; clarification: z.ZodOptional; annotation: z.ZodOptional; }, z.core.$strict>>>; }, z.core.$strict>; activations: z.ZodDefault; targets: z.ZodArray>; clarification: z.ZodOptional; }, z.core.$strict>>>; authority: z.ZodDefault; source: z.ZodUnion; repository: z.ZodString; commit: z.ZodString; tree: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"package">; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"command">; command: z.ZodString; args: z.ZodDefault>; executableDigest: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"stdio">; resolver: z.ZodEnum<{ npx: "npx"; uvx: "uvx"; }>; registry: z.ZodPipe>; package: z.ZodString; version: z.ZodString; integrity: z.ZodString; }, z.core.$strict>, z.ZodUnion; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; administrativeStatus: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"remote">; origin: z.ZodPipe>; approval: z.ZodObject<{ approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>; contentScanned: z.ZodLiteral; toolSurfaceDigest: z.ZodString; verdict: z.ZodEnum<{ approved: "approved"; drifted: "drifted"; revoked: "revoked"; }>; }, z.core.$strict>]>, z.ZodObject<{ type: z.ZodLiteral<"mcp">; server: z.ZodString; subject: z.ZodString; }, z.core.$strict>, z.ZodObject<{ type: z.ZodLiteral<"hook">; handler: z.ZodLiteral<"usage-metering">; scriptDigest: z.ZodString; }, z.core.$strict>]>; issuer: z.ZodString; sourceDigest: z.ZodString; evidenceDigest: z.ZodString; projector: z.ZodEnum<{ "framework-contract": "framework-contract"; "hook-managed-settings": "hook-managed-settings"; "mcp-managed-settings": "mcp-managed-settings"; "usage-hook": "usage-hook"; }>; policyVersion: z.ZodString; reason: z.ZodString; clarification: z.ZodOptional; scope: z.ZodArray>; notBefore: z.ZodString; expiresAt: z.ZodString; github: z.ZodObject<{ repository: z.ZodString; attestationId: z.ZodString; subjectDigest: z.ZodString; }, z.core.$strict>; }, z.core.$strict>>>; }, z.core.$strict>>; externalCuration: z.ZodDefault; items: z.ZodDefault; id: z.ZodString; source: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; }, z.core.$strict>; audit: z.ZodObject<{ record: z.ZodString; digest: z.ZodString; }, z.core.$strict>; clarification: z.ZodOptional; }, z.core.$strict>>>; }, z.core.$strict>>>; externalSelections: z.ZodDefault; items: z.ZodDefault; id: z.ZodString; source: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; }, z.core.$strict>; }, z.core.$strict>>>; }, z.core.$strict>>>; eccMcpApprovals: z.ZodDefault; sourceContentSha256: z.ZodLiteral<"a4426254c55a5352db2672bc86a87f10b0029f5e4ae1b74817841e87d9ab1e57">; state: z.ZodEnum<{ approved: "approved"; revoked: "revoked"; }>; approvedBy: z.ZodString; authenticationMode: z.ZodString; allowedDataClasses: z.ZodArray; }, z.core.$strict>>>; eccHookControls: z.ZodOptional; disabledIds: z.ZodOptional>>; }, z.core.$strict>, z.ZodTransform<{ profile: "minimal" | "standard" | "strict"; disabledIds?: string[] | undefined; }, { profile: "minimal" | "standard" | "strict"; disabledIds?: string[] | undefined; }>>>; supportedClis: z.ZodOptional>>; hookRegistrations: z.ZodDefault; spawns: z.ZodNumber; timeout: z.ZodOptional; sourceDisabled: z.ZodDefault; nativeGroup: z.ZodOptional>; nativeHook: z.ZodOptional>; owner: z.ZodDiscriminatedUnion<[z.ZodObject<{ kind: z.ZodLiteral<"aih">; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"third-party">; framework: z.ZodString; declaredControls: z.ZodDefault>; pin: z.ZodObject<{ repository: z.ZodString; commit: z.ZodString; path: z.ZodString; launcherSha256: z.ZodString; runtimeVersion: z.ZodString; }, z.core.$strict>; }, z.core.$strict>, z.ZodObject<{ kind: z.ZodLiteral<"unknown">; launcherSha256: z.ZodString; }, z.core.$strict>], "kind">; }, z.core.$strict>>>; }, z.core.$strict>]>>; }, z.core.$strict>; rings: z.ZodOptional; }, z.core.$strict>>>; }, z.core.$strict>; export type PolicyBundle = z.infer; export type PolicyRing = z.infer; export type PolicyBundleParse = { ok: true; bundle: PolicyBundle; } | { ok: false; error: string; }; /** * Parse a policy-bundle envelope into a discriminated RESULT rather than a throw * (the `readMarketplaceManifest` posture, not `parseOrgPolicy`'s): the consumer * is `aih policy validate`, a checker, so a malformed bundle is a FINDING it * must report — never a crash. One parse covers BOTH layers (the envelope * embeds {@link OrgPolicySchema}), and the error message names WHICH layer * failed: issues rooted under `policy` are the embedded org policy, everything * else is the envelope itself. */ export declare function parsePolicyBundle(value: unknown): PolicyBundleParse; export {};