#!/usr/bin/env bash
# Print every changed path that can affect validation, including both sides of
# renames. Disabling rename detection deliberately represents a move as a
# deletion plus an addition so a risky source cannot escape a path gate merely
# by moving out of its watched directory. Type changes are retained as well so
# replacing a watched regular file with a symlink cannot bypass validation.
set -euo pipefail
# Three-dot `A...B` is the merge-base of A and B versus B — the PR change set.
# Never rewrite that to first-parent (`B^1`): GitHub's pull_request merge ref
# has BASE as first parent, a local merge has the branch as first parent, and
# those two answers must agree. A stale left-hand SHA widens the set; callers
# must pass a live base ref (origin/<base>), not github.event.pull_request.base.sha.
if [ "$#" -eq 1 ] && [[ "$1" == *...* ]]; then
range="$1"
left_revision="${range%%...*}"
right_revision="${range##*...}"
merge_base="$(git merge-base "$left_revision" "$right_revision")"
set -- "$merge_base" "$right_revision"
fi
exec git diff --name-only --no-renames --diff-filter=ACMRTD "$@"