.DS_Store
.env
.env.*
!.env.example

sandbox/
node_modules/
.svelte-kit/
dist/

# Nix / direnv (flake.nix + flake.lock are committed; build outputs are not)
.direnv/
result
result-*

docs/credentials/
docs/funding/

# Access-limited local correspondence evidence. Public records contain only
# approved summaries and hashes; raw messages, headers, screenshots, contact
# channels, and exact sent attachments stay here and out of Git (ADR 0031).
.private/

.playwright-cli/

# Local Python validation bytecode
__pycache__/
*.py[cod]

# pyLODE writes a run log in the working dir (make vocab-docs)
pylode.log

# Credential-free build produced by `make smoke-static`
dist-smoke/
dist-browser/

# Written by `make validate`: when the suite last passed and on which tree.
# Local state, not a repository fact.
.validation.log

# npm auth lives here. A granular access token with 2FA bypass is a publish
# credential, and this repository is public: an `git add -A` away from being
# pushed. Never commit it. Publish config that is not secret belongs in
# package.json, not here.
.npmrc
