-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.gitignore
More file actions
98 lines (89 loc) 路 4.41 KB
/
Copy path.gitignore
File metadata and controls
98 lines (89 loc) 路 4.41 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
# Local tooling & scratch
node_modules/
tools/
.scratch/
*.log
# A version bump unpacks a throwaway harness install and drives pnpm through a
# local npm cache; both are hundreds of MB of node_modules that NOTHING in this
# repo reads (the checks resolve the pinned line from an npm install and the
# profile mirror, never from here). They are anchored to the root and spelled
# with a leading dot so a real directory of either name inside a package stays
# trackable - the same trap `/dsh-diagrams/` documents further down.
/.upgrade/
/.npm-cache/
# CREDENTIALS. Nothing of these shapes may ever be staged, because a secret in a
# commit is a secret on GitHub for as long as the repository exists - in every
# fork and every clone - even after the file is deleted. The harness keeps its
# own credentials in `$DSH_HOME/.credentials.yaml`, which defaults to `~/.dsh`
# and is therefore OUTSIDE this tree; these rules are the belt for the case where
# DSH_HOME is pointed inside it, or a copy is dropped here by hand.
# `scripts/checks/check-no-secrets.mjs` asserts every line below still exists AND
# fails the build if a credential-shaped string reaches any staged file.
.env
.env.*
.credentials.yaml
*.credentials.yaml
*.pem
*.key
*.p12
*.pfx
id_rsa*
id_ed25519*
.netrc
# An .npmrc can carry a registry token. Nothing in this pack needs one (it ships
# zero npm dependencies); if you ever need a committed one, force-add it.
.npmrc
# The DISTRIBUTION folder built by run-dist.bat / dist.sh. It is a COPY
# of this repository (minus the trees listed in scripts/dist-manifest.txt) plus
# the built shell binary, and it is a build OUTPUT like any other: it is rebuilt
# by one command, it is regenerated per platform in CI, and nothing in it is
# content. It must never be committed - a 22 MB tree of copies would also make
# every plugin edit show up twice in a diff.
dist/
# The SECOND output folder. `run-dist.bat -OutDir dist2` (or any other path)
# exists because a distribution that is RUNNING holds its own vncode.exe
# open, and Windows refuses to overwrite or delete a file in use - so a new cut
# has to be assembled somewhere else and swapped in once the window is closed.
# Build output for exactly the same reasons as dist/ above.
dist2/
# The VENDORED RUNTIME built by scripts/dsh/vendor.ps1: runtime/<rid>/node plus
# the whole pinned harness tree the shell launches instead of npx (~545 MB). It
# is build output - resolved from the pin, reproducible by one command - and
# committing it would put a 461 MB dependency tree in every clone and fork.
/runtime/
# The desktop shell's Rust build tree (app/). Cargo writes hundreds of
# megabytes of objects and binaries under app/src-tauri/target/, and none of it
# is content: `run-desktop.bat` rebuilds it, and a fresh clone builds it once.
# The icons BESIDE it are the opposite - generated by
# scripts/make-desktop-icon.mjs and committed, so a clone can build without
# running the generator first.
app/src-tauri/target/
# tauri-build also writes ACL/capability JSON schemas into gen/schemas on every
# build, for editor completion. Nothing in the repository reads them, they are
# regenerated by any `cargo build`, and this shell exposes no IPC command and no
# capability of its own - so they are build output, not content.
app/src-tauri/gen/
# The diagram DATABASE must never be committed. dsh-diagrams keeps one file per
# conversation plus one shared library under $DSH_HOME/dsh-diagrams/, and
# $DSH_HOME defaults to ~/.dsh (outside this repo). These rules are the belt for
# the case where DSH_HOME is pointed inside the tree, or a copy is dropped here.
#
# They are ANCHORED to the repository root on purpose. An unanchored
# `dsh-diagrams/` also matches `packages/dsh-diagrams/` - the PACKAGE of the same
# name - which silently ignored all 18 of its tracked files, so the NEXT file
# added inside that package would have been invisible to `git status` and skipped
# by `git add -A`: present locally, passing local tests, never committed.
# check-no-secrets.mjs fails if any tracked file is ignored, which is what keeps
# these two rules anchored.
/dsh-diagrams/
/library.json
# Exported diagram sources are LOCAL material, not repo content: they are
# verbatim copies of what the library stores, so committing them would put the
# diagram database on GitHub in another form. docs/diagrams/ stays on the
# machine that exported it, with its own drift check beside it.
docs/diagrams/
# Editors / OS
.DS_Store
Thumbs.db
.vscode/
.idea/