import type { Finding, Severity } from '../types.js'; /** * A finding is "proposed" when its HIPAA reference cites the NPRM (the proposed * 2026 Security Rule), not a current obligation. Such findings are still shown, * but they must not inflate a group's headline severity. */ export declare function isProposedFinding(f: Finding): boolean; /** * Split findings into CURRENT obligations and PROPOSED (NPRM) ones. Proposed * findings are rendered in their own "Upcoming Requirements" subsection and are * excluded from the current-severity Scan Summary, so a proposed rule is never * shown as a current red/critical violation. */ export declare function partitionFindingsByStatus(findings: Finding[]): { current: Finding[]; proposed: Finding[]; }; /** Stable ordering for the proposed-requirements list: by file, line, title. */ export declare function sortProposedFindings(findings: Finding[]): Finding[]; /** One screen entry: findings that share a (file, line, rule category). */ export interface LocationGroup { key: string; file: string; line: number | undefined; /** Rule category shared by all members (the "family"). */ category: string; /** Headline severity — highest among CURRENT (non-proposed) members. */ severity: Severity; /** Members, sorted highest-severity first then by title. */ members: Finding[]; } /** * Group findings by (file + line + rule category). Several rules that flag the * same line for the SAME reason (e.g. all PHI-in-logs on route.ts:36) collapse * into one entry; unrelated rules on the same line (e.g. MFA + backup) stay as * separate rows. A single-member group renders as a normal row. * * The headline severity reflects only CURRENT requirements — proposed (NPRM) * findings never raise it (they stay listed inside with their own badge). When * every member is proposed, the highest proposed severity is used. * * Groups are ordered by group severity (critical first), then file, line, and * category. The total member count always equals the input length — nothing is * dropped. */ export declare function groupFindingsByLocation(findings: Finding[]): LocationGroup[]; /** Count location-groups by their group severity (for summary/filter labels). */ export declare function countGroupsBySeverity(groups: LocationGroup[]): Record; /** * Count findings by their OWN severity — one tally per finding. Unlike * countGroupsBySeverity (which counts location groups, so collapsing inflates * nothing but deflates the visible numbers), this matches the raw per-severity * numbers the Executive Summary uses, so the report shows the SAME counts in the * summary cards, the recommendations, and the filter chips. * * Proposed (NPRM) findings must be excluded by the caller — pass only the * current findings so a proposed rule never lands in a current-severity bucket. */ export declare function countFindingsBySeverity(findings: Finding[]): Record; /** * Render a file path for display relative to the scan target root. A white-label * report an agency hands to its client must never leak the developer's absolute * machine path or username, so an absolute path is always reduced to a path * relative to the scan root (e.g. "src/app/api/patients/route.ts"). Already- * relative paths are returned unchanged; an absolute path that escapes the root * falls back to its basename rather than leaking the full path. */ export declare function toRelativeDisplayPath(file: string, root: string): string; /** * Normalize any hipaaReference string to one canonical style: * "45 CFR §164.312(c) — Integrity Controls". * * Handles the three styles currently emitted by the scanners: * - already-full "45 CFR §164.312(c) - Integrity Controls" * - bare section "§164.502, §164.514" * - NPRM-prefixed "NPRM §164.312(d) - Person or Entity Authentication" * → kept distinct as a proposed rule: * "45 CFR §164.312(d) — Person or Entity Authentication (NPRM — proposed rule)" * * Multi-section refs (comma-separated) are expanded into each canonical ref, * joined with "; ". The original string is never mutated on the finding object. */ export declare function formatHipaaRef(raw: string | undefined | null): string; //# sourceMappingURL=finding-presentation.d.ts.map