import { type SpawnSyncReturns } from "node:child_process"; export declare const CREDENTIAL_PURPOSES: readonly ["git-transport", "github-api", "github-admin", "reviewer"]; export type CredentialPurpose = typeof CREDENTIAL_PURPOSES[number]; export interface CredentialRef { id: string; purpose: CredentialPurpose; hostId: string; repository: string; identity: string; scopes: string[]; expiresAt: string; envVar: string; } interface ResolvedCredential { secret: string; ref: CredentialRef; } export interface CredentialResolver { resolve(ref: CredentialRef): ResolvedCredential; } interface CredentialEvidence { identity: string; repository: string; repositoryId?: string; capabilities: string[]; status: number; } /** Explicit test seam; production always uses the fixed GitHub probe below. */ export interface CredentialTestAdapter { probe(ref: CredentialRef, env: NodeJS.ProcessEnv): CredentialEvidence; } export declare function scrubSensitive(value: string, secrets?: string[]): string; export declare function runWithCredential(args: { ref: CredentialRef; purpose: CredentialPurpose; resolver: CredentialResolver; command: string; argv: string[]; requiredCapability: string; repositoryId?: string; cwd?: string; preserveFailure?: boolean; beforeDispatch?: () => void; runner?: (command: string, argv: string[], env: NodeJS.ProcessEnv) => SpawnSyncReturns; testAdapter?: CredentialTestAdapter; now?: Date; }): { status: number | null; stdout: string; stderr: string; error: string | null; credentialRef: string; identity: string; expiresAt: string; }; export {}; //# sourceMappingURL=service.d.ts.map