__pycache__/
*.pyc
*.pyo
.venv/
venv/
*.egg-info/
dist/
build/
.pytest_cache/
.superpowers/
*.db
*.key
.worktrees/
worktrees/
.cursor/grove_followup_last_id
.cursor/hooks.json
data/

# Playwright e2e (INVARIANTS §10) — installed deps and per-run output.
# `npm install` / `npx playwright test` produce these locally and in CI;
# none of it is tracked-code.
node_modules/
package-lock.json
test-results/
playwright-report/

# Nestor session store — the live SQLite and its ledger are built locally from
# nestor/session-decisions.json (`nestor import --apply`), never committed.
# LOCAL-ONLY.md's rule: the blueprint travels, the live store does not. A JSON
# bundle is also reviewable in a diff; a SQLite file is not.
nestor/*.db
nestor/*.db-shm
nestor/*.db-wal
nestor/*.ledger.jsonl

# Live envelope register — the ratifications actually in force on THIS box.
# `envelopes/pre-approved.json` is written by willow-mcp (envelope_propose /
# envelope_ratify) as the seat works; it is machine state, not law. The law is
# `syscall-table.json` (what verbs exist and their bounds signatures) and
# `README.md` — those stay tracked.
#
# Same rule as the Nestor session store above: the blueprint travels, the live
# store does not. Tracking it meant every clone inherited another machine's
# active grants as if they were its own. `grove/envelope_reader.py` handles the
# file's absence (logs once, returns no envelopes), so a fresh clone now fails
# CLOSED with zero grants — which is the correct default for a register of
# authority. LOCAL-ONLY.
envelopes/pre-approved.json
