# ---------------------------------------------------------------------------
# nearmiss — .gitignore
#
# Hard rule #4 (contributor privacy) is enforced here first: precise raw
# reports never enter version control. Only aggregated, jittered, published
# artifacts under data/published/ are committed.
# ---------------------------------------------------------------------------

# Private precise reports — NEVER commit (deanonymization risk).
data/raw/
data/raw/**
*.raw.geojson
*.private.json

# Public-submission moderation queue — precise pending/approved reports, private
# like data/raw/. Only aggregated, published artifacts are ever committed (HR4).
# Matched at any depth (e.g. data/real/<city>/pending/) so a moderation store can
# never be committed regardless of where a config's submissions_dir resolves.
data/pending/
data/pending/**
**/pending/
**/pending/**

# Real-city working tree: fetched inputs and isolated outputs from the real-data
# pipeline (BikeMaps + OSM + counts). Not committed — fetch it locally; the
# committed published dataset stays the reproducible demo. See docs/REAL-DATA.md.
data/real/
data/real/**

# Secrets — env only, never committed (see SECURITY.md).
.env
.env.*
!.env.example
*.pem
*.key
secrets/
.secrets/

# Python
__pycache__/
*.py[cod]
*$py.class
*.egg-info/
.eggs/
build/
dist/
.installed.cfg
*.egg
pip-wheel-metadata/

# Virtual environments
.venv/
venv/
env/
ENV/

# Tooling caches
.pytest_cache/
.mypy_cache/
.ruff_cache/
.coverage
.coverage.*
htmlcov/
coverage.xml
.tox/
.nox/
.hypothesis/

# Mutation testing (mutmut) — advisory only; its working copy and stats are
# regenerated on every run and must never be committed (see docs/MUTATION-TESTING.md).
mutants/
.mutmut-cache
mutmut-stats.json
mutmut-cicd-stats.json
html/

# i18n pseudo-locale (G9 gate) — the build-only "xx" catalog must never ship under
# the package locales tree. tools/make_pseudolocale.py already refuses to write
# there (see tests/test_pseudolocale.py::test_pseudo_catalog_never_ships_under_package_locales);
# this is defense in depth for the same invariant against an older tool version or
# a manual run. See docs/I18N.md.
src/nearmiss/locales/xx/
src/nearmiss/locales/xx-build/

# Notebooks
.ipynb_checkpoints/

# Node / web tooling (accessible map build)
node_modules/
web/dist/
web/.cache/
npm-debug.log*

# Generated analysis artifacts (regenerated by `make reproduce`)
notebooks/_build/
*.tmp.geojson
/tmp/

# Per-run provenance manifests (publish writes <slug>.run.json next to the open
# GeoJSON). Regenerated every run and carries an unhashed wall-time sidecar, so it
# is NOT byte-stable and must never be committed; the hashed provenance section is
# the reproduce tripwire, asserted in tests, not by a committed file.
*.run.json

# OS / editor noise
.DS_Store
Thumbs.db
*.swp
.idea/
.vscode/
*~
