_site/
.jekyll-cache/
.jekyll-metadata
.sass-cache/
Gemfile.lock
vendor/
node_modules/

# Generated by aggregate.py (CI creates these at build time)
_data/chokepoints.yml
assets/js/search-index.json
_chokepoints/

# Weekly TTP update script caches
scripts/.mitre_cache.json
scripts/__pycache__/

# Enrichment pipeline intermediate cache (rebuilt each run)
cache/*

# Local environment — copy .env.example and fill in keys; never commit
.env
.env.local
.env.*

# Cache dir is gitignored but the placeholder file is kept
!cache/.gitkeep

# Python bytecode
__pycache__/
*.py[cod]

# Streamlit secrets
.streamlit/secrets.toml

# Local test output
/tmp/masq_infra_test.json

# Local AI / assistant tooling (machine-specific; not part of the published site)
.claude/
.cursor/skills-cursor/

# OS / editor noise
.DS_Store
Thumbs.db
Desktop.ini
*.swp
*~

# Local preview / mockups (remove these lines to track in git)
preview.html
framework-mockup.html

# Internal / non-site material — keep out of the public repo
.planning/
drafts/
mockups/
docs/ATTEMPTS.md
docs/DECISIONS.md
docs/M3-PROVENANCE-PLAN.md
scripts/enrich_staging_domains.py
# Local ASN/IP enrichment tooling + inputs (touch IPs/keys/external lookups; never
# committed -- the repo holds only published site data, decision #009). These write
# only IP-free aggregates to cache/, which the page publishes.
scripts/enrich_asns.py
scripts/hll.py
scripts/bulletproof_asns.yml
