-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.gitignore
More file actions
129 lines (116 loc) · 3.64 KB
/
Copy path.gitignore
File metadata and controls
129 lines (116 loc) · 3.64 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
# ============================================================================
# ALLOWLIST MODEL (default-deny) — adopted 2026-05-31
# ----------------------------------------------------------------------------
# DEFAULT: ignore EVERYTHING. Only the paths explicitly un-ignored below are
# trackable / pushable. A stray file or directory at the repo root (env/, a new
# internal note, an accidentally-saved secret) is ignored BY DEFAULT and CANNOT
# leak — even if no one remembers to add an ignore rule. This inverts the old
# "track everything unless ignored" blocklist that let root env/ slip through.
#
# Paired enforcement: hooks/pre-push refuses any push that includes a file
# outside the allowlisted top-level paths (belt-and-braces, in case a rule here
# is mis-edited). To publish a NEW top-level path, add it to BOTH places.
# ============================================================================
# --- deny everything at the root by default ---
/*
# --- ALLOW: the publishable top-level paths (the ONLY things that can be pushed) ---
!/.gitignore
!/.github/
!/.claude-plugin/
!/.envrc.template
!/CHANGELOG.md
!/CODE_OF_CONDUCT.md
!/CONCEPT.md
!/CONTRIBUTING.md
!/LICENSE
!/README.md
!/SECURITY.md
!/STATUS.md
!/datasets/
!/docs/
!/hooks/
!/logo/
!/prototypes/
!/server-config/
!/site/
!/spec/
!/tools/
# ============================================================================
# Within-allowed re-ignores: internal / build / cache / secret files that live
# UNDER an allowed directory must still be excluded. (These also act as a second
# net even though /* already denies the root.)
# ============================================================================
# Secret-file globs (anywhere) — never track credentials even under a pub dir
.secrets/
*.pem
*.key
*.crt
*.p12
*.pfx
.env
.env.*
*.env
*.env.*
.envrc
*.envrc
secrets.*
credentials.*
*_credentials.*
*_secret.*
*_secrets.*
# Python build / venv / cache (anywhere)
__pycache__/
*.pyc
*.pyo
*.egg-info/
.venv/
venv/
.venv-pw/
.pytest_cache/
.mypy_cache/
.ruff_cache/
build/
dist/
# Databases
*.db
*.db-journal
*.db-wal
*.db-shm
# Node
node_modules/
# OS / IDE / tooling artifacts
.DS_Store
Thumbs.db
.idea/
.vscode/
.playwright-mcp/
*.ipynb_checkpoints
*.jpeg
*.playwright-screenshot.png
# Local editor/backup snapshots (never publish stale copies)
*.bak
*.bak-*
*~
# Local-only helper tools that live under tools/ (allowed dir) but are internal
tools/anp2_chrome_launch_cdp.sh
tools/mail_dev_check.sh
# Inbound-actor triage engine — coupled to the gitignored internal/ defense
# policy + signatures; keep the whole subsystem internal, don't telegraph posture.
tools/inbound_triage.py
# Article-comment watcher — engagement-ops tooling; keep local (same posture
# reasoning as inbound_triage: don't telegraph the followup machinery).
tools/article_comment_watch.py
# HuggingFace dataset binaries (separate HF repo via LFS). Metadata under
# datasets/ stays tracked; only the large snapshots are excluded.
datasets/anp2-events/anp2-events.parquet
datasets/anp2-events/anp2-events.jsonl
# Exception: ship the TypeScript SDK build artifacts so the npm package is
# publishable without the operator needing Node/tsc locally. (Overrides dist/.)
!prototypes/anp2-client-js/dist/
!prototypes/anp2-client-js/dist/**
# ============================================================================
# NOT listed above (therefore ignored by the /* default-deny) and intentionally
# kept OUT of the public repo: internal/ env/ CLAUDE.md .claude/ public/
# node_modules/ and anything else newly dropped at the root. Do NOT add !rules
# for these.
# ============================================================================