export interface IntegrityResult { /** Critical helper names whose on-disk hash doesn't match the signed manifest * (or that are missing from disk despite being part of the signed set). */ tampered: string[]; /** Set only when the package's OWN signed manifest can't be verified at all — * there's no ground truth to check the installed files against, distinct * from a clean `tampered: []` result. */ blocked?: string; } /** * Re-verify each of `criticalHelpers` present on disk in `helpersDir` against * `sourceDir`'s signed manifest. Read-only — safe to call without holding any * refresh lock; callers only need to acquire one if `tampered` comes back * non-empty and they intend to repair it. * * `sourceDir: null` (package source unresolvable) returns `{ tampered: [] }` * — fails open rather than flagging every install as tampered when there is * no ground truth at all to compare against. */ export declare function verifyInstalledCriticalHelpers(helpersDir: string, sourceDir: string | null, criticalHelpers: readonly string[], pubkeyPemOverride?: string): IntegrityResult; //# sourceMappingURL=helper-integrity.d.ts.map