import type { Posture } from "../config/posture.js"; import { type ProbeAction } from "../internals/plan.js"; import type { Check } from "../internals/verify.js"; import type { ConfigSecretHit, SecretScan } from "./scan.js"; /** * Stable SARIF rule id shared by every plaintext-secret finding. One rule, many * results (one per path) — so GitHub code-scanning groups all exposures under a * single rule, exactly as the drift gate uses one stable `drift` id rather than a * per-instance name. {@link reportToSarif} dedupes rules by check name, so every * probe carries this same `name`; the per-path detail keeps each result distinct. */ export declare const SECRET_RULE = "plaintext-secret"; export declare function plaintextSecretCheck(path: string, posture: Posture): Check; /** * One read-only probe per detected plaintext-secret path. Posture decides whether * it is warning-only (`vibe`) or a failing gate (`enterprise`); only failing * verdicts flip the exit code and render as SARIF errors. * * Pure and boundary-safe: the scan already read the filesystem at plan-build time, * so the probe just returns its precomputed verdict — it spawns nothing, contacts * no remote, and mutates nothing. A probe is a read-only verdict carrier, never a * mutation, so this stays within the harness's no-remote-mutation contract. The * detail names only the offending PATH, never any secret value, so no plaintext * material is ever emitted. */ export declare function secretProbes(scan: SecretScan, posture: Posture): ProbeAction[]; /** Stable SARIF rule id for hardcoded-secret-in-config findings (one rule, many results). */ export declare const MCP_SECRET_RULE = "mcp-hardcoded-secret"; export declare function mcpConfigSecretCheck(hit: ConfigSecretHit, posture: Posture): Check; /** * One read-only probe per MCP config finding. Like {@link secretProbes}, the scan * ran at plan-build time so each probe just carries its posture-graded verdict — * no spawn, no remote, no mutation. The detail names the FILE + KEY + match kind, * never the secret value, so no plaintext material is emitted. */ export declare function mcpConfigSecretProbes(hits: ConfigSecretHit[], posture: Posture): ProbeAction[];