# VCS .git .gitignore # Dependencies **/node_modules .pnpm-store # Build output dist coverage # Local environment files (a committed .env.example lands in E00-S04) **/.env **/.env.* # Secrets & credentials (E00-S02-T08) — never part of the build context, so a # secret-bearing file cannot be embedded in the image even if a developer has # one locally. Every pattern is `**/`-prefixed because Docker's matcher # (moby/patternmatcher) anchors a slash-less pattern to the context ROOT — a # bare `.npmrc`/`*.key`/`secrets` would exclude nothing under `apps/server/…`. # `**/` matches the file at the root AND at any nested depth. Keep this list # in sync with tests/secrets-not-embedded.test.mjs. **/.npmrc **/.netrc **/.credentials **/.aws **/.ssh **/secrets **/*.pem **/*.key **/*.p12 **/*.pfx **/*.jks **/id_rsa **/id_ed25519 # Logs *.log