node_modules/
coverage/
dist/
.cache/
# W270 — Playwright capture output. The CANON-053 evidence record is the
# hash-bound docs/visual-qa/LATEST.json; the PNGs themselves are regenerable
# local artifacts (14MB+ of binary churn per visual wave does not belong in git).
output/
.env
.env.*
!.env.example
*.log
audits/mcp-keys.json
audits/*.key
audits/*.pem
audits/grants-secret.key
audits/oidc-signing-key.pem
# S321 — the post-quantum signing key. `audits/*.pem` already covered the ES256
# key, but the ML-DSA key persists as an RFC 9964 AKP *JWK* whose `priv` member is
# the 32-byte seed, so it is a PRIVATE KEY with a .jwk extension that no existing
# pattern matched. Glob, not just the literal, so a rotation sibling
# (pq-signing-key.prev.jwk / .next.jwk) cannot be committed either.
audits/pq-signing-key*.jwk
audits/*.lock
context/.session-lock
STUDIO_AI_MODEL_v2_mobile_frontier_research.docx
STUDIO_AI_MODEL_v2_mobile_frontier_research.html
.ops-cache/
secrets/

# stale root session-lock (canonical lock is context/.session-lock)
.session-lock

# Python
__pycache__/
*.pyc

.secrets/

# W141 deploy artifact — stamped by gate-deploy.mjs per deploy, never source
build-info.json

# W214 — ledger reconciliation backup written by scripts/dedupe-cache-ledger.mjs
# (git history is the real backup; the .bak is a local safety net, never source)
*.ndjson.bak

# Atomic-write temp files (never commit interrupted .tmp debris — W230)
audits/.*.tmp
*.tmp

# W239 — propagation quarantine. The guard copies every landed blob here before
# removing it, so a rejected propagation is always recoverable. Local forensic
# state, not repo content: committing it would add the very clobber the guard
# just rejected. audits/propagation-log.jsonl is the committed, append-only
# record of what happened.
.quarantine/
