# ── Python ──────────────────────────────────────────────────
__pycache__/
*.py[cod]
*.egg-info/
*.egg
build/

# ── Test / lint / type caches ──────────────────────────────
.mypy_cache/
.pytest_cache/
.ruff_cache/
.coverage
.coverage.*
htmlcov/
coverage/
.tox/

# ── Virtual environments ───────────────────────────────────
.venv/
venv/
env/

# ── IDE / editor ───────────────────────────────────────────
.idea/
.vscode/
*.swp
*.swo
*~

# ── OS ─────────────────────────────────────────────────────
.DS_Store
Thumbs.db

# ── Environment files (keep examples + frontend prod) ─────
# .env.production for the frontend has no secrets — it points at the
# same-origin Firebase Hosting rewrite. Keeping it tracked means anyone
# redeploying gets the prod config without manually recreating the file.
.env
.env.*
!.env.example
!frontend/.env.production

# ── Docker / databases ─────────────────────────────────────
pgdata/
*.db
*.sqlite
*.sqlite3

# ── uv ─────────────────────────────────────────────────────
backend/.python-version

# ── Node / Vite / Next ─────────────────────────────────────
node_modules/
.next/
dist/
.vite/
*.tsbuildinfo

# ── Logs ───────────────────────────────────────────────────
*.log
logs/

# ── Archives / bundles (not source) ────────────────────────
*.zip
*.tar
*.tar.gz
*.tgz

# ── Firebase ───────────────────────────────────────────────
# Per-machine deploy cache; firebase.json + .firebaserc stay tracked.
.firebase/
firebase-debug.log
firestore-debug.log
ui-debug.log

# ── Claude Code per-machine state ──────────────────────────
# scheduled_tasks.lock + settings.local.json are local to the operator,
# not part of the repo's shared config.
.claude/

# ── Misc ───────────────────────────────────────────────────
.cache/
tmp/
*.pid
messages.json

# ── Design handoff (generated static mockups) ──────────────
design-handoff/

# Google service-account JSON keys — NEVER commit. Local dev keys live in
# backend/.secrets/ (vertex-sa.json, maia-sa.json) and are gitignored as a
# directory so a new key dropped in won't accidentally leak. Prod uses
# Secret Manager / workload identity instead.
backend/.secrets/
# Legacy patterns kept so any straggler key at the repo root still gets caught.
/trusty-vim-*.json
/maia-493810-*.json
*-service-account*.json
*-gcp-key*.json
*-vertex*.json

client_secret_497788162142-r2a24nb8hl679nloc43jiqctpvmbb5v8.apps.googleusercontent.com.json
# Claude Code skill artifacts (local tooling, not app code)
.agents/
skills-lock.json
scratchpad.md

# ── Desktop (Electron) ──────────────────────────────────────
# build/ above is a Python pattern; desktop/build holds source-controlled
# packaging resources (icon, entitlements). dist output stays ignored.
!desktop/build/
desktop/dist/
