# Python
__pycache__/
*.py[cod]
*.egg-info/
.pytest_cache/
.mypy_cache/
.ruff_cache/

# Secrets / runtime state — NEVER commit
.env
*.env
config.yaml
.hermes-data/
.hermes/

# Local runtime / generated
build/
.okengine/effective-policy.json
.okengine/policy-coverage.json
.okengine/qualification/
# generated by cron_pack_split.py from engine-crons + pack (trailing text on the
# pattern line is NOT a git comment — keep the comment on its own line)
config/cron-plus-jobs.json

# Editor / tooling
.claude/
.serena/
.vscode/
.idea/
*.swp

# Local-only engineering notes (reference private origin systems / absolute paths —
# kept out of the engine repo per the no-domain-knowledge / no-deployment-paths rule)
docs/origin-system-review.md
# private scrub-check regexes for the pre-commit leak grep (see CLAUDE.md)
.scrub-patterns

# Scratch / backups
*.bak
*.bak.*
scratch/
tmp/
*.log

# invariant-audit run artifacts (findings reference internal/domain detail; the script+README are tracked, outputs are not)
scripts/audit/last-run-*.md

# local audit triage working file (references finding content)
.audit-triage.md

# coverage artifacts (make coverage / --cov)
.coverage
.coverage.*
coverage.json
artifacts/
htmlcov/
