/**
 * @license
 * Copyright 2025 Google LLC
 * SPDX-License-Identifier: Apache-2.0
 */
import { URL } from 'node:url';
import * as dns from 'node:dns';
import { ProxyAgent } from 'undici';
/**
 * Error thrown when a connection to a private IP address is blocked for security reasons.
 */
export declare class PrivateIpError extends Error {
    constructor(message?: string);
}
export declare class FetchError extends Error {
    code?: string | undefined;
    constructor(message: string, code?: string | undefined, options?: ErrorOptions);
}
/**
 * Sanitizes a hostname by stripping IPv6 brackets if present.
 */
export declare function sanitizeHostname(hostname: string): string;
/**
 * Checks if a hostname is a local loopback address allowed for development/testing.
 */
export declare function isLoopbackHost(hostname: string): boolean;
/**
 * A custom DNS lookup implementation for undici agents that prevents
 * connection to private IP ranges (SSRF protection).
 */
export declare function safeLookup(hostname: string, options: dns.LookupOptions | number | null | undefined, callback: (err: Error | null, addresses: Array<{
    address: string;
    family: number;
}>) => void): void;
export declare function isPrivateIp(url: string): boolean;
/**
 * Checks if a URL resolves to a private IP address.
 * Performs DNS resolution to prevent DNS rebinding/SSRF bypasses.
 */
export declare function isPrivateIpAsync(url: string): Promise<boolean>;
/**
 * Internal helper to check if an IP address string is in a private or reserved range.
 */
export declare function isAddressPrivate(address: string): boolean;
/**
 * Enhanced fetch with SSRF protection.
 * Prevents access to private/internal networks at the connection level.
 */
export declare function safeFetch(input: RequestInfo | URL, init?: RequestInit): Promise<Response>;
/**
 * Creates an undici ProxyAgent that incorporates safe DNS lookup.
 */
export declare function createSafeProxyAgent(proxyUrl: string): ProxyAgent;
/**
 * Performs a fetch with a specified timeout and connection-level SSRF protection.
 */
export declare function fetchWithTimeout(url: string, timeout: number, options?: RequestInit): Promise<Response>;
export declare function setGlobalProxy(proxy: string): void;
