import { RemovalPolicy } from 'aws-cdk-lib';
import { IRepository } from 'aws-cdk-lib/aws-ecr';
import { RetentionDays } from 'aws-cdk-lib/aws-logs';
import { Construct } from 'constructs';
import { ScanLogsOutput } from './scan-logs-output';
import { Severity, Scanners, ImageConfigScanners } from './types';
/**
 * Properties for ImageScannerWithTrivy Construct.
 *
 * @deprecated Use ImageScannerWithTrivyV2Props instead. This will be removed in the next major version.
 */
export interface ImageScannerWithTrivyProps {
    /**
     * Image URI for scan target.
     */
    readonly imageUri: string;
    /**
     * Repository including the image URI for scan target.
     *
     * Because of grantPull to CustomResourceLambda.
     */
    readonly repository: IRepository;
    /**
     * The unfixed/unfixable vulnerabilities mean that the patch has not yet been provided on their distribution.
     *
     * To hide unfixed/unfixable vulnerabilities, you can use the `--ignore-unfixed` flag.
     *
     * @default false
     *
     * @see https://aquasecurity.github.io/trivy/latest/docs/scanner/vulnerability/#unfixed-vulnerabilities
     */
    readonly ignoreUnfixed?: boolean;
    /**
     * Severity Selection
     *
     * The severity is taken from the selected data source since the severity from vendors is more accurate.
     * Using CVE-2023-0464 as an example, while it is rated as "HIGH" in NVD, Red Hat has marked its 'Impact' as "Low". As a result, Trivy will display it as "Low".
     *
     * The severity depends on the compile option, the default configuration, etc. NVD doesn't know how the vendor distributes the software.
     * Red Hat evaluates the severity more accurately. That's why Trivy prefers vendor scores over NVD.
     *
     * It defaults to `CRITICAL` IN THIS CONSTRUCT for safety in CI/CD, but the default configuration of Trivy is "CRITICAL,HIGH,MEDIUM,LOW,UNKNOWN".
     *
     * @default [Severity.CRITICAL]
     *
     * @see https://aquasecurity.github.io/trivy/latest/docs/scanner/vulnerability/#severity-selection
     */
    readonly severity?: Severity[];
    /**
     * Enable/Disable Scanners
     *
     * You can enable/disable scanners with the `scanners`.
     *
     * For example, container image scanning enables vulnerability (VULN) and secret scanners (SECRET) by default.
     * If you don't need secret scanning, it can be disabled by specifying Scanners.VULN only.
     *
     * @default [Security.VULN,Scanners.SECRET]
     *
     * @see https://aquasecurity.github.io/trivy/latest/docs/configuration/others/#enabledisable-scanners
     */
    readonly scanners?: Scanners[];
    /**
     * Enum for ImageConfigScanners
     *
     * Container images have configuration. docker inspect and `docker history` show the information according to the configuration.
     * Trivy scans the configuration of container images for
     *
     * - Misconfigurations
     * - Secrets
     *
     * They are disabled by default. You can enable them with `imageConfigScanners`.
     *
     * @default []
     *
     * @see https://aquasecurity.github.io/trivy/latest/docs/target/container_image/#container-image-metadata
     */
    readonly imageConfigScanners?: ImageConfigScanners[];
    /**
     * Exit Code
     *
     * Use the `exitCode` option if you want to exit with a non-zero exit code.
     *
     * You can specify 0 if you do not want to exit even when vulnerabilities are detected.
     *
     * It defaults to 1 IN THIS CONSTRUCT for safety in CI/CD. In the original trivy, it is 0.
     *
     * @default 1
     *
     * @see https://aquasecurity.github.io/trivy/latest/docs/configuration/others/#exit-code
     */
    readonly exitCode?: number;
    /**
     * Exit on EOL
     *
     * Sometimes you may surprisingly get 0 vulnerabilities in an old image:
     *  - Enabling --ignore-unfixed option while all packages have no fixed versions.
     *  - Scanning a rather outdated OS (e.g. Ubuntu 10.04).
     *
     * An OS at the end of service/life (EOL) usually gets into this situation, which is definitely full of vulnerabilities.
     * `exitOnEol` can fail scanning on EOL OS with a non-zero code.
     *
     * It defaults to 1 IN THIS CONSTRUCT for safety in CI/CD. In the original trivy, it is 0.
     *
     * @default 1
     *
     * @see https://aquasecurity.github.io/trivy/latest/docs/configuration/others/#exit-on-eol
     */
    readonly exitOnEol?: number;
    /**
     * By Finding IDs
     *
     * The ignore rules written to the .trivyignore in trivy.
     * Put each line you write in the file into one element of the array.
     *
     * @example
     *     $ cat .trivyignore
     *     # Accept the risk
     *     CVE-2018-14618
     *
     *     # Accept the risk until 2023-01-01
     *     CVE-2019-14697 exp:2023-01-01
     *
     *     # No impact in our settings
     *     CVE-2019-1543
     *
     *     # Ignore misconfigurations
     *     AVD-DS-0002
     *
     *     # Ignore secrets
     *     generic-unwanted-rule
     *     aws-account-id
     *
     * @default []
     *
     * @see https://aquasecurity.github.io/trivy/latest/docs/configuration/filtering/#trivyignore
     */
    readonly trivyIgnore?: string[];
    /**
     * Memory Size (MB) for Scanner Lambda
     *
     * You can specify between `3008` and `10240`.
     *
     * If this Construct execution terminates abnormally due to SIGKILL, try a larger size.
     *
     * Default value (`3008` MB) is Maximum Lambda memory size for default AWS account without quota limit increase.
     *
     * @default 3008
     */
    readonly memorySize?: number;
    /**
     * Scan Image on a specific Architecture and OS
     *
     * By default, Trivy loads an image on a `linux/amd64` machine.
     *
     * To customize this, pass a `platform` argument in the format OS/Architecture for the image, such as `linux/arm64`
     *
     * @default -
     */
    readonly platform?: string;
    /**
     * The removal policy to apply to Scanner Lambda's default log group
     *
     * If you use ImageScannerWithTrivy construct multiple times in the same stack, you cannot set different removal policies for the default log group.
     * See `Notes` section in the README for more details.
     *
     * @default - Scanner Lambda creates the default log group(`/aws/lambda/${functionName}`).
     */
    readonly defaultLogGroupRemovalPolicy?: RemovalPolicy;
    /**
     * The number of days log events are kept in Scanner Lambda's default log group
     *
     * If you use ImageScannerWithTrivy construct multiple times in the same stack, you cannot set different retention days for the default log group.
     * See `Notes` section in the README for more details.
     *
     * @default - Scanner Lambda creates the default log group(`/aws/lambda/${functionName}`) and log events never expire.
     */
    readonly defaultLogGroupRetentionDays?: RetentionDays;
    /**
     * Configuration for scan logs output
     *
     * By default, scan logs are output to default log group created by Scanner Lambda.
     *
     * Specify this if you want to send scan logs to other than the default log group.
     *
     * Currently, only `cloudWatchLogs` is supported.
     *
     * @default - scan logs output to default log group created by Scanner Lambda(`/aws/lambda/${functionName}`)
     */
    readonly scanLogsOutput?: ScanLogsOutput;
    /**
     * Suppress errors during rollback scanner Lambda execution
     *
     * When image scanning fails, CloudFormation triggers a rollback and executes the previous
     * version of the scanner Lambda. If this property is set to `true`, the previous version of
     * the scanner Lambda will not throw an error, even if the image scanning for the previous version
     * fails.
     *
     * This allows the rollback to complete successfully, avoiding ROLLBACK_FAILED state
     * when image scanning failures occur.
     *
     * @default true
     */
    readonly suppressErrorOnRollback?: boolean;
}
/**
 * A Construct that scans container images with Trivy.
 * It uses a Lambda function as a Custom Resource provider to run Trivy and scan container images.
 *
 * @deprecated Use ImageScannerWithTrivyV2 instead. This will be removed in the next major version.
 */
export declare class ImageScannerWithTrivy extends Construct {
    constructor(scope: Construct, id: string, props: ImageScannerWithTrivyProps);
    /**
     * Validates that specified default log group options are the same for existing default log group.
     */
    private validateLambdaDefaultLogGroupOptions;
    /**
     * Creates the default log group for Scanner Lambda if it does not exist.
     *
     * This method checks if the default log group for Scanner Lambda exists in children of the stack construct.
     * If it does not exist, it creates the default log group for Scanner Lambda as a child of the stack construct.
     */
    private ensureLambdaDefaultLogGroup;
    private isSameResourceDeletionBehavior;
}
