__pycache__/
*.py[cod]
*.egg-info/
.eggs/
# NOTE: this project ships a real `build/` content folder (build-all scripts) and
# builds with hatchling (output goes to dist/), so we do NOT ignore build/.
dist/
.venv/
venv/
ft-venv/
env/
.pytest_cache/
.mypy_cache/
.ruff_cache/
.coverage
htmlcov/
# SmartPangolin's own generated artifacts live one level up, but ignore them if run in-tree:
extracted_source/
share_archive/
file_folder_tree.txt
file_folder_path.txt
# Never commit real secrets:
.env
.secret/
!.secret/.gitignore
# ...except the intentional demo fixture that the scanner demo relies on:
!demo/repo/.env

# secrets and credentials never belong in the repository
.secure/
secrets.env
*.env
.env.*
!.env.example
.npmrc
.pypirc
.netrc
_netrc
id_rsa*
id_ed25519*
*.key
*.pem
*.p12
*.pfx

# port build output
*.class
ports/java/out/
ports/go/pangolin-check
ports/go/pangolincheck

# test and demo fixtures (fake values) that are tracked on purpose
!demo/repo/.env
!demo/repo/deploy/id_rsa

# binary from `go build` in ports/go (the module path ends in /go)
ports/go/go
