node_modules/
.npm/
dist/
coverage/
.wrangler/
.wrangler.drifted-backup-*/
.pytest_cache/
__pycache__/
*.pyc
*.db
.DS_Store
.env
.env.*
!.env.example
.dev.vars
.local-test-key
Cargo.lock
.vercel

# Build artifacts — these are generated and must never be tracked.
# (Web deploys rebuild from source via `wrangler pages deploy out`.)
.next/
apps/web/out/
*.tsbuildinfo

# Xcode build output (provider app)
apps/provider/build/

# Local tool scratch dirs
.claude/
apps/web/.claude/

# Playwright E2E artifacts (apps/web)
apps/web/playwright-report/
apps/web/test-results/
apps/web/.playwright/

# Local scratch — never tracked (internal notes, draft reviews)
tmp/
.venv

# Device reliability reset snapshots (rollback data, never tracked)
scripts/.reliability-snapshots/

# Credentials and signing material.
#
# Nothing of this kind has ever been committed — history was swept for it on
# 2026-08-07 and came back clean. These rules exist so that stays true by
# construction rather than by attention. The one that matters most is
# `*.key`: the Sparkle EdDSA private key signs what every provider Mac
# auto-installs (apps/provider/build-dmg.sh names it sparkle_ed_private.key),
# so committing it would hand someone code execution on the whole fleet.
*.key
*.pem
*.p12
*.p8
*.pfx
*.cer
*.der
*.keystore
*.jks
*.mobileprovision
*.provisionprofile
*.keychain
*.keychain-db
id_rsa
id_ed25519
.npmrc
.pypirc
.netrc
secrets.json
credentials.json
gha-creds-*.json

# Signed disk images. The notarized release DMG is published to R2/Pages, not
# committed — and a stray one is ~100 MB of binary in the history forever.
# apps/web/public/downloads/.gitignore already excludes them there; this covers
# build output and scratch copies anywhere else. No negation: a rule in a
# nested .gitignore wins over one here, so a `!` line would be inert and would
# read as a promise this file cannot keep.
*.dmg

# SPM build artifacts — the live tool-calling harness
# (apps/provider/Tests/ToolCallingLive) resolves mlx-swift + mlx-swift-lm into
# its own .build, which is hundreds of MB of checkouts and object files.
.build/
