# Build outputs
build/
out/
cmake-build-*/
*.o
*.obj
*.exe
*.dll
*.dylib
*.so
*.a
*.lib
*.pdb
*.ilk
*.exp

# CMake
CMakeFiles/
CMakeCache.txt
cmake_install.cmake
CTestTestfile.cmake
_deps/
compile_commands.json

# Large third-party sources/binaries (libobs, vendor SDKs) — fetched by a
# setup script, never committed directly
third_party/
vendor/

# IDE / editor
.vs/
.vscode/
*.user
.idea/
*.swp
*~

# OS cruft
.DS_Store
Thumbs.db
desktop.ini

# Logs / local scratch
*.log
.scratch/

# Ad hoc local debugging tools and their output (CDP scripts, a throwaway
# static-file server, saved frame screenshots) — real, useful during
# development, but never meant to be committed. Root-level only (not a
# blanket *.ps1/*.png, in case the project ever adds a real committed
# PowerShell build script or a real bundled asset at the repo root) —
# found with no matching rule at all during the 2026-09-28 security audit,
# which is exactly how a one-off debug script with something sensitive
# pasted into it for a single session could end up in public git history.
/*.ps1
/*.png
/scratch/

# Gift art (SVGA/webp) lives on Cloudflare R2 (cdn.tapylapy.com/liveps/...) and is fetched at runtime; this is only the local source copy.
assets/liveps/

# Release output of scripts/package-studio.ps1 (signed manifest + the whole app, hundreds of MB)
dist/
