/** * Convert a gitignore-style glob into a RegExp that is tested against a * project-relative POSIX path (file or directory). * * - A pattern without `/` matches a basename at any depth (`fixtures`, `*.generated.ts`). * - A pattern containing `/` is anchored to the project root (`legacy/e2e`, `tmp/**`). * - `**` spans directories, `*` matches within a segment, `?` matches one character. */ export declare function globToRegExp(pattern: string): RegExp; /** Build a predicate that reports whether a project-relative path matches any ignore glob. */ export declare function createIgnoreMatcher(patterns: string[]): (relativePath: string) => boolean; /** True when `target` resolves to one of `roots` or somewhere beneath one of them. */ export declare function isWithinRoots(target: string, roots: string[]): boolean; /** * Enforce the `scan.allowedRoots` policy. When no roots are configured every path is * allowed. Returns the resolved path; throws a descriptive error otherwise. */ export declare function assertWithinAllowedRoots(target: string, roots: string[], label: string): string; //# sourceMappingURL=scanPolicy.d.ts.map