# What must never reach a commit, and why.
#
# This is a security package, so the cost of a mistake here is asymmetric: a
# missing cache entry is noise, a committed key is an incident. Patterns are
# grouped by consequence rather than by tool, and the secret group is first.

# --- Credentials and key material -------------------------------------------
# .env.example is the committed template and is deliberately excluded from the
# exclusion. Everything else shaped like an environment file stays local.
.env
.env.*
!.env.example
*.pem
*.key
*.p12
*.pfx
# Certificate stores exported for local troubleshooting.
*.sst
# The lab's development pepper. It keeps local password hashes and sessions
# valid across restarts, which makes it a credential even though it is synthetic.
.roadshield-dev-secret

# --- Local databases --------------------------------------------------------
# These hold seeded customer records, conversations, and the signed audit
# ledger. Synthetic today, but the habit of committing them is the problem.
*.db
*.db-shm
*.db-wal

# --- Environments and caches ------------------------------------------------
.venv/
venv/
.uv-cache/
__pycache__/
*.py[cod]
.pytest_cache/
.ruff_cache/
.mypy_cache/

# --- Build output -----------------------------------------------------------
dist/
build/
*.egg-info/
.dist-check/

# --- Generated by CI, never committed ---------------------------------------
# The workflow regenerates these on every run. A stale copy in the repository
# would look authoritative while describing an older dependency set.
requirements.lock.txt
sbom*.json
results.sarif
gitleaks-report.json
.coverage
htmlcov/

# --- Working notes ----------------------------------------------------------
# A personal design document and its plain-text extraction. Kept local: it was
# written as private notes rather than for readers, and it describes the
# pre-0.3.0 architecture, so publishing it would point people at a design this
# package no longer has. README.md is the authoritative description.
llm-security-field-guide.html
guide-extracted.txt
