# Dependencies node_modules/ # Build output dist/ .dist/ # Environment — NEVER commit secrets at rest (DB passwords, OIDC secrets, encryption key, # Fastmail app passwords). Ignore .env and every .env.* variant, but keep the example template. .env .env.* !.env.example # Editor .vscode/ .idea/ *.swp *.swo # Claude Code local (per-machine) settings — never tracked .claude/settings.local.json # OS .DS_Store Thumbs.db # Logs *.log npm-debug.log* pnpm-debug.log* # TypeScript *.tsbuildinfo # Drizzle migrations (generated — not secrets, but keep clean) # apps/api/src/db/migrations/ # Test coverage coverage/ .nyc_output/ # Playwright CLI artifacts + ad-hoc screenshots (local verification only) .playwright-cli/ gate2-*.png # Operator-only credential seed (run out-of-band; never tracked) apps/api/scripts/seed-credential.mjs # Graphify build cache (regenerable; committed artifacts live in .planning/graphs/) graphify-out/ # Intel / graph diff baselines (local-only; regenerated on each refresh/build) .planning/intel/.last-refresh.json .planning/graphs/.last-build-snapshot.json .planning/graphs/.last-build-status.json .planning/research/.cache/ # Transient workflow scratch .planning/tmp/ # Playwright e2e harness outputs (regenerated every run; Phase 7 mobile test harness) apps/pwa/test-results/ apps/pwa/playwright-report/ apps/pwa/blob-report/ # MemPalace per-project files (issue #185) mempalace.yaml entities.json