# ---- Python ----
__pycache__/
*.py[cod]
*$py.class
*.so
.Python
build/
dist/
develop-eggs/
downloads/
eggs/
.eggs/
sdist/
wheels/
*.egg-info/
*.egg
.installed.cfg
MANIFEST

# ---- Virtual environments ----
.venv/
venv/
env/
ENV/

# ---- Packaging / dependency managers ----
# A committed lockfile gives reproducible installs; the cache is not committed.
.uv/
pip-wheel-metadata/

# ---- Testing / coverage / type / lint caches ----
.coverage
.coverage.*
coverage.xml
htmlcov/
.cache/
.pytest_cache/
.mypy_cache/
.dmypy.json
dmypy.json
.ruff_cache/
.hypothesis/
.tox/
.nox/

# ---- Secrets and keys (this project handles encryption keys) ----
.env
.env.*
!.env.example
*.pem
# Public certificate generated only for the committed synthetic site sample.
!site/sample-packet/synthetic-timestamp-authority.pem
# A public timestamp authority's own published certificates, committed as a
# golden fixture so authority trust is exercised offline against a certificate
# this repository did not generate (issue #159). Public artefacts, no private
# key material; provenance in tests/golden/tsa-freetsa/README.md.
!tests/golden/tsa-freetsa/*.pem
*.key
*.keys
secrets/

# ---- Evidence data: NEVER commit real or local case data ----
# habitable's entire premise is that tenant data lives only on tenant devices.
# Sealed case vaults, exported packets, and synced state must not enter git.
case-vault/
case-vaults/
vaults/
*.habitable
*-packet.pdf
exports/
local-cases/

# ---- Editors / IDEs ----
.idea/
.vscode/
*.swp
*.swo
*~
*.sublime-project
*.sublime-workspace

# ---- OS cruft ----
.DS_Store
.DS_Store?
._*
.Spotlight-V100
.Trashes
ehthumbs.db
Thumbs.db
desktop.ini

# ---- Agent / local scratch (not part of the project) ----
.claude/
/tmp/
scratch/
*.local

# Local productionization plan (working doc — intentionally not published)
docs/productionization.md
