# Debug artifacts
sorftime_mcp_raw_responses.json
coverage.json
/ind/
/tcs_cdx.txt

# Next.js generated type shim (regenerated by `next dev`/`next build`/`next
# typegen`); committing it just causes churn across apps. Next.js convention.
next-env.d.ts
# One-off captures from backend/debug_amazon_html.py (HTML + trafilatura markdown dumps)
backend/_debug_amazon_*.html
backend/_debug_amazon_*.md

# Claude Code (local only)
.claude/plans/
.claude/reference/
.claude/reviews/
.claude/scheduled_tasks.lock
.worktrees/

# Reference repos (local dev only)
.reference/
yc.md
# Dependencies
node_modules/
.pnp
.pnp.js

# Build outputs
.next/
public/shared/
out/
build/
dist/
.turbo/
.vercel/

# Environment
.env
.env*.local
.env_development
.env_staging
.env_production
.env_testing


# Python
__pycache__/
*.py[cod]
*$py.class
*.so
.venv/
venv/
*.egg-info/
.mypy_cache/
.test_durations.local
.test_durations.local.*.tmp
.test_node_manifest.local.json
.test_node_manifest.local.json.*.tmp
.coverage-run.lock
.typecheck.tsbuildinfo
.playwright-mcp/
.dmypy.json
.ruff_cache/
.pytest_cache/
.coverage
.coverage.*
coverage.xml
htmlcov/

# IDE
.vscode/
.idea/
*.suo
*.ntvs*
*.njsproj
*.sln
*.sw?
.cursor/

# OS
.DS_Store
Thumbs.db
desktop.ini

# Local file uploads (dev only — production uses cloud storage)
backend/uploads/
backend/test_uploads/
test_uploads/
backend/tmp/
# Per-database applied-migration hashes (scripts/check_migration_integrity.py)
backend/.migration_hashes.json

# Research / reference files
*.pdf
sandbox-file-persistence-research.md
user_interview/
plan/
# Root-only: the internal PM docs/ folder. apps/docs/ (Mintlify customer docs) is tracked.
/docs/

# backend/evals/ is a tracked Python package; only artifacts + machine-specific config are ignored.
backend/evals/workspaces/
backend/evals/history/
backend/evals/reports/
backend/evals/runs/
backend/evals/**/__pycache__/
backend/evals/**/.pytest_cache/
# pgbouncer has hardcoded absolute paths + plain-text dev creds; keep local.
backend/evals/pgbouncer/

# E2B template staging dir (mirrors backend/skills/ minus internal content)
backend/.build_staging/

# Skill translation cache. Per-skill JSON map of {english_sha256: translation}
# regenerated by `python -m scripts.skill_translate`. Cache survives `.skill-zh/`
# folder wipes so re-runs on unchanged English are no-ops; safe to delete.
backend/.translation-cache/

# Claude Code transcripts (timestamp-named files in backend/)
backend/*.txt

# MCP config (machine-specific, may contain credentials)
.mcp.json
Product-Catalog-511360-2025-11-18.xlsx
# Test artifacts. `MagicMock/` at ANY depth: the leak reproduces wherever the
# pytest process's CWD is (measured at the repo root, 2026-08-23), and the seam
# is stubbed in test_task_pool.py -- this rule is the backstop, not the fix.
MagicMock/

# Misc
*.log
backend/logs/
npm-debug.log*
yarn-debug.log*
yarn-error.log*
coverage/
package-lock.json
# EXCEPTION: the sandbox-runtime CLIs are npm (not pnpm) and are built inside the
# E2B template image with `npm ci`, which HARD-FAILS without a committed lock.
# Without this negation the template build only works on the machine that has the
# untracked lockfile on disk (LAUNCH-239).
!backend/sandbox_runtime/**/package-lock.json
uv.lock

# Sentry wizard writes auth token here on re-runs; keep it out of git.
.env.sentry-build-plugin

# Skill masters are local-only FDE content: hand-authored, published to the
# platform via dashboard zip upload. Intentionally untracked.
# Leading slash anchors this to the repo-root admin/ dir only, so it does NOT
# also swallow apps/admin/ (the staff-admin console app, which must be tracked).
/admin/

# FDE engagement workspaces: local-only customer material (raw arrivals,
# extracted text, seed state). Root-anchored like /admin/ above.
/engagements/

# skill-creator eval workspaces: run outputs may contain customer material.
# An explicit path, NOT a *-workspace glob (which would swallow seed-workspace itself).
/.claude/skills/seed-workspace-workspace/
/.claude/skills/invert-artifact-workspace/
.vercel

# Local eval/calibration run artifacts (regenerable; never commit)
backend/trials/
backend/calib_*.json
backend/stdout.json

# Harness bake-off fixtures: staged workspaces cut from REAL customer material
# (evidence bytes, contracts, case banks) plus the transcripts and payloads the
# arms produce. Never committable, under any circumstances.
backend/.bakeoff-data/

# The extraction golden pack: 3.3 MB of decoded Aurora Home evidence text
# ("customer material pasted by hand", per its own README) plus the hand census
# derived from it. Same rule as the bake-off fixtures above and the same reason:
# it is CUSTOMER MATERIAL and does not go in git.
#
# NOT REGENERABLE, and the earlier note here claimed otherwise. Half the pack is
# RECORDED INPUT, not output: `corpus/<uuid>.txt` (the 34 decoded evidence text
# layers) and `reports/g1.md..g5.md` + `reports/groups.json` (the 2026-08-24
# hand census, 827 items) were pasted in once from a session scratchpad that no
# longer exists. `make record-extraction-golden`
# (cli/scripts/record_extraction_golden.py) only re-DERIVES the other half --
# census.jsonl, ledger.jsonl, MANIFEST.json, README stats -- FROM those recorded
# inputs, and refuses outright when they are absent. So the recorded halves are
# unreconstructable if this working tree loses them: they are held only by
# whoever holds the engagement's material, and there is no durable location for
# them today. Anyone who needs the pack copies those two directories in from
# that holder (see the recorder's own refusal message) before running the
# recorder.
#
# The suites that read it -- `grep -rl extraction_golden backend/tests/`, named
# that way because the hand-written list drifted: it carried
# `test_extraction_canary_audit.py`, a file that exists nowhere in the tree, so
# a reader chasing the pack was sent to a suite nobody could run. They skip PER
# TEST on its absence; ignoring the directory does not delete it, and
# `git clean -fd` does not reach it (only `-x` does).
backend/tests/fixtures/extraction_golden/

# Running implementation log (deviations belong in the plan file, not the repo)
/implementation-notes.md

# Session research memos and lane reports (working documents, not repo content —
# the durable record is the plan ledger; the files stay on disk, untracked)
/scratchpad/

# api-types-check hook scratch dirs (mktemp-suffixed; leftovers appear when a
# run is killed mid-check and must never be committable)
packages/api/.api-types-check.*/

# Rendered-page verification screenshots dropped in the repo root by review
# sessions (the "UI fixes land on the RENDERED page" rule); evidence for a
# chat, never repo content. Twelve of them were one `git add -A` from a commit
# on 2026-08-25.
/*.png
