.DS_Store
Thumbs.db
/venv/
/venv.old/
/venv.stale.runtime-*/
/bin/
/.subnaut-runtime/
*.pyc*
__pycache__/
# Root-level scratch dirs (nektos/act state, datagen output, downloads). Anchored:
# unanchored, each also hid every nested dir of that name (a skill's examples/,
# a doc's images/, website/src/data/) from `git add`.
/act/
# No trailing slash, so a symlinked .venv is ignored too.
.venv
.vscode/
.idea/
.mypy_cache/
.coverage
.coverage.*
htmlcov/
# Secrets. .env.example is the tracked template.
.env
.env.*
!.env.example
.op.env
.subnaut-docker/
.pip-cache/
.uv-cache/
# Export dumps in the checkout root. Anchored: unanchored, it also ignored every
# new source file whose name starts with "export" (agent/export_utils.py, ...).
/export*
logs/
/data/
.pytest_cache/
test_durations.json
.pytest-cache/
/tmp/
temp_vision_images/
subnaut-*/*
/examples/
# No trailing slash: also matches node_modules SYMLINKS (worktrees often
# symlink node_modules to the main checkout; the dir-only pattern let one
# slip into a commit and break `npm ci` on CI with ENOTDIR).
node_modules
browser-use/
agent-browser/
# Private keys and certificates
# release-signing-key.pem lives under the release box's own state (~/.config/subnaut-release/),
# never in the tree -- these patterns are the backstop for a copy made into a checkout.
release-signing-key*
*.ppk
*.pem
*.key
*.p12
*.pfx
id_rsa*
/images/
subnaut_agent.egg-info/
wandb/
playwright-report/
test-results/
# Playwright visual regression baselines — cached from main in CI, not committed
*-snapshots/

# CLI config (may contain sensitive SSH paths)
cli-config.yaml

# Skills Hub state (lives in ~/.subnaut/skills/.hub/ at runtime, but just in case)
skills/.hub/
ignored/
.worktrees/

# Leftovers of the removed browser UI (build output, build lock, synced assets,
# node_modules): kept ignored so checkouts that built it before stay clean.
subnaut_cli/web_dist/
.web_ui_build.lock
/web/
apps/desktop/build/
apps/desktop/dist/

# tsc-emitted artifacts (a stray `tsc -b` compiles into src/, and vite then
# resolves the stale .js OVER the .tsx — never track these)
apps/desktop/src/**/*.js
apps/desktop/src/**/*.js.map
apps/desktop/src/**/*.d.ts
!apps/desktop/src/global.d.ts
!apps/desktop/src/vite-env.d.ts

# Build/debug artifacts that must never be committed
/log.txt
/*.png.bak
*.tar.gz
*.tgz
apps/shared/src/**/*.js
apps/shared/src/**/*.js.map
apps/shared/src/**/*.d.ts
apps/desktop/release/
# stage-and-swap Desktop rebuild output (#86443); removed after the swap, but
# a killed build must not leave the checkout dirty
apps/desktop/.staging-*/
*.tsbuildinfo

# Nix
.direnv/
.nix-stamps/
result
website/static/api/skills-index.json
# skills.json + skills-meta.json are build artifacts emitted by
# website/scripts/extract-skills.py during prebuild — keep them out of
# git for the same reason as skills-index.json (large, generated, change
# every build).
website/static/api/skills.json
website/static/api/skills-meta.json
# automation-blueprints-index.json is a build artifact emitted by
# website/scripts/extract-automation-blueprints.py during prebuild.
website/static/api/automation-blueprints-index.json

# Local editor / agent tooling (machine-specific; keep in global config, not the repo)
.codex/
.cursor/
.gemini/
.zed/
.mcp.json
opencode.json
config/mcporter.json
# Specs and plans the superpowers agent plugin writes into the working tree
docs/superpowers/*

subnaut_cli/tui_dist/*
# Working directory for the Subnaut Agent's session state (~/.subnaut/ at runtime;
# also created in-repo when an agent operates in this checkout). Plans, audit
# logs, and per-session caches are never artifacts of the codebase.
.subnaut/

# SUBNAUT_HOME state written straight into the checkout root when something runs
# with SUBNAUT_HOME pointing at the repo (seen 2026-09-18). sessions/, pairing/,
# mcp-tokens/, auth.json and state.db hold transcripts and credentials, so they
# must never be picked up by `git add -A`. logs/ is covered by the rule above.
# cron/ and skills/ are real source directories and cannot be listed here.
/sessions/
/pairing/
/memories/
/hooks/
/audio_cache/
/image_cache/
/mcp-tokens/
/auth.json
/.anthropic_oauth.json
/state.db*
.skills_prompt_snapshot.json

# Desktop/bootstrap install marker written into the managed checkout root by the
# bootstrap installer. It is Subnaut-managed runtime state, never a code change —
# ignore it so `subnaut update`'s `git stash push --include-untracked` does not
# treat it as a local edit and autostash it on every run (#38529).
.subnaut-bootstrap-complete

# Persistent dev sandbox dir (scripts/dev-sandbox.sh --persistent)
.subnaut-sandbox/
# Sandbox dirs used by the install/update E2E (tests/install/). The suffix is
# the route name, so each route gets its own tree and two can run at once.
.subnaut-sandbox-e2e*/

# Interrupted-update breadcrumb + recovery lock written next to the shared venv
# by `subnaut update` / launch-time self-heal. Runtime state, never a code change
# — ignore so `git status` stays clean and update's autostash skips them.
.update-incomplete
.update-incomplete.lock

# Checkout fingerprint the __pycache__ tree was last validated against
# (launch-time stale-bytecode sweep). Runtime state, never a code change.
.bytecode-fingerprint
.bytecode-fingerprint.tmp

# Installer-written method stamp in the managed checkout root (scripts/install.sh).
# Runtime metadata only — never a code change. Ignore so `git status` stays clean
# and `subnaut update`'s untracked autostash does not treat it as a local edit (#66189 / #54855).
/.install_method

# Tool Search live-test harness output — non-deterministic model transcripts,
# regenerated by scripts/tool_search_livetest.py. Never an artifact of the repo.
scripts/out/

native/fts5_cjk/*.so
# Runtime marker written by subnaut update when a lazy dependency refresh is
# interrupted; consumed by launch-time recovery. Never commit it (was tracked
# by accident via 3a69e34702, removed in the #72002 salvage).
.lazy-refresh-incomplete

# Disposable profile created by scripts/probe_active_session_exclusivity.py
.probe-home/

# Release artifacts (scripts/build_release.py)
/dist/
