# Dependencies
node_modules/

# Build artifacts (npm pack / vsce package output — never commit)
*.tgz
*.vsix

# Internal research (not part of the public package)
Research/

# Environment files
.env
.env.local
.env.development
.env.production

# OS files
.DS_Store
Thumbs.db

# IDE
.vscode/
.idea/
*.swp
*.swo

# Build artifacts
dist/
build/
coverage/

# DocGuard generated docs (for THIS project testing)
# Note: In real projects, docs-canonical/ SHOULD be committed.
# These are excluded here because they're template-generated test files.
docguard_cli/__pycache__/
.venv/
dist/
*.egg-info/
__pycache__/
.venv
.docguard/

# Local security-scan artifacts (websec-validator) — contains fixture findings, machine-local
websec-out/

# OpenWolf private session memory (machine-local, not shared)
.wolf/
# Everything this repository had under .claude/ was OpenWolf-local and useless in
# a fresh clone: settings.json registered five hooks running .wolf/hooks/*.js, and
# rules/openwolf.md told agents to consult .wolf/ files that a clone does not have
# — the same defect as .codex/hooks.json below. Swept in by a `git add -A` in
# fc73116, a validator-fix commit that also captured all of .wolf/. Ignored as a
# directory so no future sweep can repeat it. OpenWolf is optional local tooling:
# `openwolf init` regenerates .wolf/ and these files. Project instructions that
# every contributor needs belong in AGENTS.md and CLAUDE.md, which stay tracked.
# Exception: the Spec Kit core skills (`specify init --integration claude`) are
# the workflow every change in this repository runs through, so a fresh clone
# must have them. DocGuard's own extension skills (speckit-docguard-*) are copies
# of extensions/spec-kit-docguard/ and are regenerated by `npm run speckit:dev`.
.claude/*
!.claude/skills/
.claude/skills/*
!.claude/skills/speckit-*/
.claude/skills/speckit-docguard-*/
# Local agent tooling: .codex/hooks.json points at .wolf/hooks/*.js, which this
# repository ignores, so shipping it hands contributors a config referencing
# scripts they do not have. Committed by mistake in f1fef7a; ignored here so a
# future `git add -A` cannot repeat it.
.codex/
.testguard/

# Spec Kit downloads the community extension catalog into this cache, keyed by
# URL hash and stamped with a `cached_at` time. It is regenerated on demand from
# the catalog_url each entry records, so committing it ships a frozen snapshot
# (2026-03-17) that silently ages while looking authoritative. First swept in by
# 96e2dd8. The rest of .specify/ (templates, scripts, constitution) is source and
# stays tracked.
.specify/extensions/.cache/
# `specify extension add extensions/spec-kit-docguard --dev` copies this
# repository's own extension into .specify/extensions/docguard/ and writes the
# hook registry. A committed copy would be a second source for the same files,
# drifting from extensions/ with every edit. `npm run speckit:dev` regenerates it.
.specify/extensions/
.specify/extensions.yml

# safeWrite leaves a `.bak` beside any file it overwrites. Those are local
# recovery artifacts, never source. `cli/precision-evidence-data.mjs.bak` was
# swept into ee3fc88 by a `git add -A` and shipped a frozen copy of a GENERATED
# module — a near-duplicate that drifts further from the real numbers with every
# regeneration, and that a grep for a precision value will happily find first.
*.bak
