# Docker secrets
.env
Server/.env

# Claude Code — local-only by default. The exceptions are committed on purpose:
# a cloud session clones this repo and sees ONLY tracked files, so the CLAUDE.md
# files, skills and workflows have to be here or it starts with no instructions.
# Machine-local state (settings.local.json, locks) stays ignored.
.claude/*
!.claude/skills/
!.claude/workflows/
!.claude/settings.json
CLAUDE.local.md
.mcp.json

# GitHub Copilot instructions (internal)
.github/copilot-instructions.md
.github/instructions/

# Agent worktrees (Mission Control fleet isolation)
.worktrees/

# AI-specific / internal planning docs
docs/brain/
docs/CODEMAPS/
docs/designs/
docs/research/
docs/superpowers/
/skills/

# Detailed security reports for findings that are not yet fixed. This repo is
# public (docs/security.md): reproduction traces for a live defect must never
# be committed. Findings are coordinated through private GitHub Security
# Advisories; only opaque identifiers and safe status go in tracked plans.
docs/security-findings/

# Mutation-testing output (npm run test:mutate). Local-only by design: a
# surviving-mutant report maps exactly which behaviour nothing tests.
Client/.stryker-tmp/
Client/reports/

# Server runtime artifacts
Server/chatserver.exe
Server/chatserver.exe~
Server/owncord-server.exe
Server/server.exe
Server/config.yaml
Server/data/

# Prebuilt plugin example (RL-08). Built from the main.go beside it with the
# TinyGo toolchain that directory's README pins. Read by nothing in the build
# or test graph, and not byte-reproducible on another machine: TinyGo embeds
# absolute host paths from the building machine's Go SDK and module cache, and
# has no -trimpath equivalent.
#
# Deliberately NOT a blanket *.wasm rule. Client/public/rnnoise.wasm is a
# vendored npm artifact this repository does not build and the client fetches
# at runtime; ignoring it would break voice noise suppression.
Server/plugin/examples/hello/hello.wasm

# Test coverage artifacts
*.out
Server/cov.out
Server/cover.out
Server/coverage.out
Server/ws_cover.out
Server/ws_cov.out

# Client build artifacts
Client/publish/
Client/publish-single/
Client/publish-release/

# HTML mockups (large design reference files)
Client/login-mockup.html
Client/ui-mockup.html

# Tauri typegen (auto-generated IPC bindings)
Client/src/generated/
.typecache

# Node modules
node_modules/

# AI tooling
.gstack/
.claude-flow/
.rust-review-results/

# Bug-hunt ledger: shared so contributors can add findings. Only the ledger and
# its renderer are tracked; hunt transcripts, .bak snapshots and debris patches
# are per-session scratch and stay local.
#
# FINDINGS.md is deliberately NOT tracked (RL-07): it is 100% derived from
# findings-ledger.json, and every hunt would otherwise write a fresh ~1.06 MB
# blob into permanent history for a file a reader can regenerate in under a
# second with `node .superpowers/render-ledger.mjs`.
.superpowers/*
!.superpowers/findings-ledger.json
!.superpowers/render-ledger.mjs

.claude/worktrees/

# Internal dev tools (e.g. tools/livekit-server.exe) are ignored, but the
# owncord-introspect MCP server is a committed, shared dev tool.
tools/*
!tools/mcp-introspect/
tools/mcp-introspect/node_modules/
.cache/

# Internal dev files (root-level scratch only)
/SKILL.md
TODOS.md
DESIGN.md
Client/CLIENT-REVIEW.md

# Agent tooling state
.serena/

# Client env (holds API keys - never commit)
Client/.env

# Rust review output
.rust-review-results/

# Claude Code worktrees (local scratch, never commit)
.claude/worktrees/

# local server run logs
server.log

# Knowledge-graph output. The tool and its 20.41 MB tracked payload were removed
# in a5f7d95 (#1413, RL-06). The rule stays so a machine that still has the local
# directory — it reached ~208 MB with cache and dated snapshots — does not see it
# as untracked noise.
graphify-out/
