# VCS
.git
.gitignore

# Dependencies
**/node_modules
.pnpm-store

# Build output
dist
coverage

# Local environment files (a committed .env.example lands in E00-S04)
**/.env
**/.env.*

# Secrets & credentials (E00-S02-T08) — never part of the build context, so a
# secret-bearing file cannot be embedded in the image even if a developer has
# one locally. Every pattern is `**/`-prefixed because Docker's matcher
# (moby/patternmatcher) anchors a slash-less pattern to the context ROOT — a
# bare `.npmrc`/`*.key`/`secrets` would exclude nothing under `apps/server/…`.
# `**/` matches the file at the root AND at any nested depth. Keep this list
# in sync with tests/secrets-not-embedded.test.mjs.
**/.npmrc
**/.netrc
**/.credentials
**/.aws
**/.ssh
**/secrets
**/*.pem
**/*.key
**/*.p12
**/*.pfx
**/*.jks
**/id_rsa
**/id_ed25519

# Logs
*.log
