/** * The closed allowlist of telemetry events and their permitted property keys. * TELEMETRY.md mirrors this file. Nothing outside these sets is ever sent. * Base properties (see base-props.ts) are permitted on every event implicitly. */ export declare const BASE_PROP_KEYS: readonly ["vendoVersion", "osPlatform", "nodeVersion", "projectIdHash", "packageManager"]; /** * Cloud-lane property keys, the second half of the lane split: the anonymous * lane (no or invalid VENDO_API_KEY) is EVENT_ALLOWLIST only, and these keys * are stripped even if callers pass them; when a valid Vendo Cloud key is * present the client accepts allowlisted keys ∪ CLOUD_PROP_KEYS on EVERY * event. A closed set like the allowlist — nothing outside it is ever sent — * and TELEMETRY.md ("When Vendo Cloud is configured") documents it. The lane * markers themselves (`cloud`, `cloudKeyHash`) are producer-set in client.ts * and deliberately NOT listed here, so callers can never spoof them. */ export declare const CLOUD_PROP_KEYS: ReadonlySet; export type EventName = "init_started" | "init_completed" | "init_failed" | "doctor_run" | "command_run" | "star_prompt" | "agent_run" | "error_class"; export declare const EVENT_ALLOWLIST: Record>; /** * The events that are operational records rather than product analytics: they * say "this ran, here is how it went", and nobody funnels or retains them. * They go to PostHog's Logs product instead of `/capture/` — same key, same * consent, same allowlist, but a store with enforced 30-day retention. The * split is by destination only; an event is never sent to both. */ export declare const LOG_EVENTS: ReadonlySet;