# =========================================================================== # Secrets — NEVER commit. Enforced additionally by scripts/verify-no-secrets.sh # which is wired in as a pre-commit hook. # =========================================================================== secrets/* !secrets/*.example !secrets/*.template !secrets/.gitkeep *.env !*.env.example !*.env.template # Rendered-from-template artefacts always contain real credentials. *.rendered *.rendered.* *.local *.local.* # Pi credential and model-store files carry plaintext API keys. models.json auth.json trust.json models-store.json *.pem *.key !*.key.example *.p12 id_ed25519* id_rsa* # =========================================================================== # Backups — must live OUTSIDE this repository. # Precedent to avoid: hermes-agent-config/backups/ committed # hermes-secrets-*.tar.gz into the working tree. # =========================================================================== backups/ *.tar.gz *.tar.zst *.tgz *.zip # =========================================================================== # Runtime state that belongs to the live installation, not to config # =========================================================================== sessions/ *.jsonl !scenarios/*/eval/golden/*.jsonl .ccgram-uploads/ # =========================================================================== # Language toolchains # =========================================================================== node_modules/ .venv/ venv/ __pycache__/ *.py[cod] *.egg-info/ .mypy_cache/ .ruff_cache/ .pytest_cache/ # =========================================================================== # Editor / OS # =========================================================================== .DS_Store .idea/ .vscode/ *.swp *.orig *.rej