import { type McpTrustLedger } from '@manehorizons/cadence-types'; /** `.cadence/mcp-trust.json` — a sibling of `state.json`/`intelligence/*.json`, * never a `state.json` field (Phase 181 DRAFT Boundaries). */ export declare function trustLedgerPath(repoRoot: string): string; /** * This deliberately diverges from `state.json`/`config.json`, which hard- * throw on corrupt or invalid data (`StateCorruptError`, `ConfigInvalidError`) * and only default on a genuinely missing file. The trust ledger does not * follow that precedent: a missing file is the normal first-run case and * degrades silently to an empty ledger, but so does a present-and-corrupt * one (unparseable JSON or schema-invalid) — loudly, via a stderr notice, * but never by throwing. * * That is a fail-closed choice specific to this file: an empty ledger means * every `APPROVAL_BYPASS` MCP call subsequently finds no valid grant and is * refused, rather than the MCP server crashing mid-session over a persisted * security-grant file that a human never directly hand-edits. "No valid * data" should mean "no trust," not "take down the server." */ export declare function readTrustLedger(repoRoot: string): Promise; export declare function writeTrustLedger(repoRoot: string, ledger: McpTrustLedger): Promise; //# sourceMappingURL=store.d.ts.map