export interface PolicyException { ruleId: string; reason: string; approvedBy?: string; expiresAt?: string; files?: string[]; } export interface CompliancePolicy { frameworks: string[]; failOn: "critical" | "high" | "medium" | "low"; exceptions: PolicyException[]; requiredControls?: string[]; } export interface GuardVibeConfig { rules: { disable: string[]; severity: Record; }; scan: { exclude: string[]; maxFileSize: number; }; plugins: string[]; compliance?: CompliancePolicy; /** Custom auth function names that GuardVibe should recognize as auth guards. * e.g. ["requireAdmin", "verifyUser", "ensureLoggedIn"] * These are added ON TOP of the built-in pattern-agnostic detection. */ authFunctions?: string[]; /** Routes that are intentionally public (no auth required). * e.g. [{"path": "/blog", "reason": "Public page"}] * These are excluded from auth-coverage unprotected count. */ authExceptions?: Array<{ path: string; reason: string; }>; /** Score calculation tweaks. Default density model is "linear" (matches * pre-v3.0.50 behavior). Set to "exponential" for smoother decay past * density 5 — projects with many medium findings will see slightly higher * scores under exponential, projects with concentrated criticals will see * lower. CI gates set on absolute score should keep the default. */ scoring?: { densityModel?: "linear" | "exponential"; }; /** Slopsquat / hallucinated-package detector (`slopscan`) settings. * - online: query the npm registry for existence/age/downloads (default true for the * standalone tool; full_audit always runs offline-only regardless). * - allow: package names to treat as intentional (e.g. private/unpublished or * path-aliased imports) so they are never flagged as phantom imports. */ slopscan?: { online?: boolean; allow?: string[]; }; } export declare function loadConfig(dir?: string): GuardVibeConfig; export declare function resetConfigCache(): void;