/** * Cross-file taint analysis — tracks user input flowing across module boundaries. * Resolves imports/exports, builds a module graph, and propagates taint between files. */ import { type TaintFinding } from "./taint-analysis.js"; export interface FileEntry { path: string; content: string; } export interface CrossFileTaintFinding { source: { file: string; type: string; line: number; variable: string; }; sink: { file: string; type: string; line: number; code: string; }; chain: string[]; severity: "critical" | "high" | "medium"; description: string; fix: string; } interface ImportInfo { /** The file that contains the import statement */ importer: string; /** Resolved path of the module being imported */ source: string; /** Named imports: local name -> exported name */ names: Map; /** Default import name, if any */ defaultName?: string; /** Namespace import name (import * as X), if any */ namespaceName?: string; /** Line number of the import statement */ line: number; } interface ExportInfo { /** The file that exports */ file: string; /** Exported name -> local name */ names: Map; /** Has default export */ hasDefault: boolean; /** Default export local name (function/class name or "default") */ defaultLocal?: string; } interface FunctionSignature { file: string; name: string; params: string[]; startLine: number; endLine: number; body: string; } interface TaintedExport { file: string; exportName: string; /** Which parameter indices receive taint and flow to sinks */ taintedParams: Map; /** Whether the function returns a tainted value (param flows to return) */ returnsTainted: boolean; /** Which param indices flow through to the return value */ taintedReturnParams: number[]; } declare function normalizePath(from: string, importPath: string): string; declare function stripExtension(filePath: string): string; declare function parseImports(file: string, content: string): ImportInfo[]; declare function parseExports(file: string, content: string): ExportInfo; declare function extractFunctions(file: string, content: string): FunctionSignature[]; declare function findTaintedExports(files: FileEntry[]): TaintedExport[]; export declare function analyzeCrossFileTaint(files: FileEntry[]): { crossFileFindings: CrossFileTaintFinding[]; perFileFindings: Map; }; export declare function formatCrossFileTaintFindings(crossFileFindings: CrossFileTaintFinding[], perFileFindings: Map, format: "markdown" | "json"): string; export { parseImports, parseExports, extractFunctions, findTaintedExports, normalizePath, stripExtension };