import type { GateImpl } from './types.js'; /** * Settle-time boundary diff scan (Phase 156). Follow-on to phase 155's * edit-time `boundaryEnforcement: 'block'`, which cannot see a violation that * never passed through the host's pre-tool-edit hook (most notably a * subagent-driven edit). No-ops unless `effectiveBoundaryEnforcement` resolves * to `'block'`. Enumerates every file touched by the whole phase via an * UNSCOPED git diff (`collectUnscopedTouchedFiles`, not `ctx.touchedFiles`/ * `ctx.diff()`, which are pre-scoped to the declared `files:` set and can * structurally never surface an out-of-boundary file), drops `.cadence/**` * self-writes, and refuses when a file outside the declared `files:` union is * found — unless bypassed via `--force`/`--allow-boundary-scan-failure` and * the gate is not sealed. * * Phase 226 (T3): a genuine bypass (unsealed, `--force` or * `--allow-boundary-scan-failure` set, past a real finding) now also carries * `flags.boundaryScanBypassed: true` on the returned `GateResult` — mirroring * `test-coverage`'s `coverageBypassed` — so the registry's gate-provenance * collection can report this as "skipped (bypassed)" instead of "ran". */ export declare const runBoundaryScanGate: GateImpl; //# sourceMappingURL=boundary-scan.d.ts.map