//#region src/node/git.d.ts type GitResult = { ok: boolean; stdout: string; stderr: string; }; /** * Whether a revision is safe to hand to git as a positional argument. * * `execFile` never invokes a shell, so there is no shell injection here. The * hazard is argument injection: a revision travels as its own argv entry, and * git reads any entry starting with `-` as an option. `git diff --name-only * --output=` writes that file — verified — so a revision that reaches a * git command unchecked is a file-writing flag waiting to happen. * * Today `refExists` runs first and git itself rejects those, so no caller can * actually reach that sink. That is an accident of ordering, not an invariant: * it disappears the moment someone adds a helper that takes a ref, or reorders * the guard. Validating in one place makes it an invariant. * * Hyphens, dots and slashes are legitimate *inside* a ref (`feature/a-b`, * `v1.0-rc1`) — only a leading one is the problem. Checked by code point so * the intent (reject control characters and whitespace) is explicit. */ declare function isSafeRef(ref: string): boolean; declare function isInsideWorkTree(cwd: string): boolean; /** Absolute repository root, or null when `cwd` is not inside a git work tree. */ declare function repoRoot(cwd: string): string | null; /** Whether the ref resolves to a commit that exists in this (possibly shallow) clone. */ declare function refExists(cwd: string, ref: string): boolean; /** * The merge-base SHA between `ref` and HEAD, or null when it cannot be computed * (shallow clone with the base outside history, unrelated histories, unknown * ref). A null here is the signal that `vitest --changed ` would silently * diff against nothing and pass green — the caller must fall back to a full run. */ declare function mergeBase(cwd: string, ref: string): string | null; /** * The set of changed files Vitest's `--changed` would consider, as repo-root- * relative posix paths: committed changes since the diff point, plus staged, * plus untracked/modified working-tree files. `diffAgainst` is a resolved SHA * (merge-base) for a ref-based run, or null for a bare working-tree run. * * Run this from the repository root (`repoRoot`) so every git subcommand agrees * on the path base: `git diff` reports repo-root-relative paths, but `git * ls-files` reports cwd-relative and cwd-scoped paths unless given `--full-name` * and run from the top — mixing the two (e.g. from a monorepo package dir) * yields duplicated, inconsistent keys. */ declare function changedFiles(repoRootDir: string, diffAgainst: string | null): string[]; //#endregion export { GitResult, changedFiles, isInsideWorkTree, isSafeRef, mergeBase, refExists, repoRoot };