# --- 1. PYTHON: BYTECODE, BUILD, PACKAGING ---
# Compiled bytecode and packaging output — all regenerated by the build, never source.
__pycache__/
*.py[cod]
*.egg-info/
.eggs/
build/
dist/

# --- 2. VIRTUAL ENVIRONMENTS (uv) ---
# `uv sync --all-extras` recreates these. uv.lock IS committed, for reproducible builds.
.venv/
venv/
.uv/

# --- 3. TOOLING CACHES ---
# ruff, mypy, pytest, coverage — local speed-ups, never useful in Git.
.mypy_cache/
.ruff_cache/
.pytest_cache/
.coverage
htmlcov/

# --- 4. SCAN ARTIFACTS ---
# What `webvigil scan` / `webvigil report` write to disk. Ephemeral by design.
*.sarif
scan-*.json
scan-*.html
reports/

# --- 5. LOCAL DATABASES ---
# The Web API's SQLite file — created per machine, holds local scan history only.
*.sqlite3
*.db
*.db-shm
*.db-wal

# --- 6. WEB UI (Next.js) ---
# web/ has its own .gitignore; these catch its build output from the repo root too.
web/node_modules/
web/.next/
web/out/
web/.env*.local
# Lighthouse CI reports (.github/workflows/lighthouse.yml).
.lighthouseci/

# --- 7. SECRETS AND LOCAL CONFIG ---
# Real secrets and machine-specific overrides. There is no committed .env;
# webvigil.example.toml is the config template.
.env
webvigil.local.toml

# --- 8. EDITOR AND OS ---
.idea/
.vscode/
.DS_Store
Thumbs.db

# --- 9. LOCAL PLANNING / SCRATCH NOTES ---
# Superseded by specs/ once a feature is designed; never part of history.
/*.plan.md
.plans/
