# .ci-fingerprint is deliberately NOT excluded: it is the CI cache barrier # that keeps the check stages from replaying a cached pass. See the lint # stage of the Dockerfile. .git/ bin/ # Third-party browser assets are fetched and hash-verified inside the build by # script/fetch-assets. Excluding any host copy keeps a developer's working tree # from supplying the bytes that get shipped. The script and its # static/vendor.sha256 manifest stay in the context. static/js/alpine.min.js *.md LICENSE .editorconfig .env .env.* *.db *.sqlite *.sqlite3 .DS_Store .idea/ .vscode/ tmp/ temp/