/** * GitHub Actions OIDC (Release Governance Architecture §8, Signing v2). * * When `govern --post` runs inside GitHub Actions with `id-token: write`, it * requests a short-lived OIDC token and attaches it to the decision post. The * server verifies the token's repository + commit claims, so a decision is * provably produced by a workflow in that repo at that commit — not * fabricated from a laptop with a valid license. Outside Actions this returns * null and the decision posts unattested (still recorded, marked so). */ export declare const OIDC_AUDIENCE = "enterprise-skills"; /** * Request an Actions OIDC token for {@link OIDC_AUDIENCE}. Returns null when * not running in Actions or when id-token permission was not granted. */ export declare function requestActionsOidcToken(fetchImpl?: typeof fetch, env?: NodeJS.ProcessEnv): Promise; //# sourceMappingURL=oidc.d.ts.map