# See https://docs.github.com/en/get-started/getting-started-with-git/ignoring-files for more about ignoring files.

# compiled output
dist
tmp
out-tsc

# Playwright
test-results/
playwright-report/
playwright-smoke-report/
blob-report/
playwright/.cache/

# dependencies
node_modules

# IDEs and editors
/.idea
.project
.classpath
.c9/
*.launch
.settings/
*.sublime-workspace

# IDE - VSCode
.vscode/*
!.vscode/settings.json
!.vscode/tasks.json
!.vscode/launch.json
!.vscode/extensions.json

# misc
/.sass-cache
/connect.lock
/coverage
/libpeerconnection.log
npm-debug.log
yarn-error.log
testem.log
/typings

# System Files
.DS_Store
Thumbs.db

# Flutter/Dart specific
.dart_tool/
.flutter-plugins
.flutter-plugins-dependencies
.packages
.pub-cache/
.pub/
**/build/
# Style Dictionary generated tokens are committed for diff review + so the
# tools/check-design-tokens.mjs check has a ground-truth snapshot to compare
# against. Un-ignore the SD output dir specifically.
!react/ui/src/tokens/build/
ios/Pods/
ios/.symlinks/
ios/Flutter/Flutter.framework
ios/Flutter/Flutter.podspec
ios/Runner/GeneratedPluginRegistrant.*
android/.gradle/
android/captures/
android/gradlew
android/gradlew.bat
android/local.properties
android/**/GeneratedPluginRegistrant.java
android/key.properties
*.jks
macos/Pods/
macos/.symlinks/
windows/flutter/
.fvm/

.nx/cache
.nx/workspace-data
.cursor/rules/nx-rules.mdc
.github/instructions/nx.instructions.md


# NestJs build output
**/dist

# Node modules
**/node_modules

# compiled output# Tests
/coverage
/.nyc_output

# Jest cache
/.jest
.jest/
/.jest-cache
.jest-cache//node_modules
/build

# Logs
logs
*.log
npm-debug.log*
pnpm-debug.log*
yarn-debug.log*
yarn-error.log*
lerna-debug.log*

# OS
.DS_Store

# Tests
/coverage
/.nyc_output

# IDEs and editors
/.idea
.project
.classpath
.c9/
*.launch
.settings/
*.sublime-workspace

# IDE - VSCode
.vscode/*
!.vscode/settings.json
!.vscode/tasks.json
!.vscode/launch.json
!.vscode/extensions.json

# dotenv environment variable files
**/.env
.env.development.local
.env.test.local
.env.production.local
.env.local
.env*
!**/.env.example
!**/.env.*.example
!.env.example
!**/.env.e2e
# canopy-mobile dev-profile runtime config: PUBLIC by design (Firebase web
# apiKey + dev API hosts, same values as the k8s webConfig ConfigMap) and
# committed so `expo start` gets the dev EXPO_PUBLIC_* vars (mobile auth E3-s3).
!apps/canopy-mobile/.env.development

# temp directory
.temp
.tmp

# Runtime data
pids
*.pid
*.seed
*.pid.lock

# Diagnostic reports (https://nodejs.org/api/report.html)
report.[0-9]*.[0-9]*.[0-9]*.[0-9]*.json

# helm/kube secrets
**/*.secret.yaml
**/*.secret.*

# migration-tool local k8s run manifests (operational scratch, not deployed via GitOps)
tools/canopy-migration-tool/k8s/

# database files
*.sqlite
*.sqlite3

# Data directories
**/data/

# backups
*.bak
*.backup
backups/

# release manifests (generated artifacts)
release-manifests/

# secrets folder
**/secrets*
vite.config.*.timestamp*

# Next.js
.next
out

vitest.config.*.timestamp*

# Python
*.py[cod]
__pycache__/
*.so
*.egg
*.egg-info/
dist-python/
build-python/
.eggs/
.pytest_cache/
.mypy_cache/
.ruff_cache/
.coverage
.coverage.*
htmlcov/
*.cover
.hypothesis/
*.log
.uv/
.venv/
venv/
ENV/
env/
pip-log.txt
pip-delete-this-directory.txt
.Python
# Ralph orchestration files
.ralph/
.ralph-task-*.md
.spec-task.md

# Canopy agent worktrees (created by /canopy-handoff via `git worktree add`)
# Registered worktrees are already excluded from `git status` by git itself; this
# entry is defensive against orphan state from failed `git worktree remove` runs
# or manual `mkdir .worktrees/...` outside the canopy-* skill flow.
.worktrees/

# tools/<name>/output/ — per-run artifacts from operator CLIs
# (e.g. tools/tenant-inventory/output/<timestamp>.{json,md}).
# Per-run manifests should never land in PRs.
tools/*/output/

.nx/polygraph
.claude/worktrees
.claude/settings.local.json

# Storybook static build outputs
react/ui/storybook-static/

# eflow story plan dirs — local scratch, exchanged via Notion Tech Notes, never committed
.plan/

# eflow session-hook runtime state — per-session bookkeeping, never committed
.eflow/

# Playwright MCP debug output (console logs, page snapshots) — local scratch
.playwright-mcp/

# Expo
node_modules/
.expo/
.yarn/
dist/
npm-debug.*
*.jks
*.p8
*.p12
*.key
*.mobileprovision
*.orig.*
web-build/
cache/


# entitlement-backfill runbook bundle artifact (docs/auth/entitlement-backfill-runbook.md)
.backfill-cli.cjs

# TypeScript incremental-build cache — machine-specific, never committed
*.tsbuildinfo

.nx/self-healing
.nx/migrate-runs

# canopy-mobile Android toolchain env (generated by apps/canopy-mobile/tools/android-setup.sh)
apps/canopy-mobile/.android-env.sh

# Warm npm cache baked into the ARC runner image at build time (see
# .github/workflows/build-runner-image.yml) — contents are generated, never committed.
.github/runner-image/npm-cache/*
!.github/runner-image/npm-cache/.gitkeep
