# Scan output is regenerated by `make casa-evidence` and is committed
# deliberately: the submission has to show what was scanned and when.
#
# What is not committed is anything containing customer data or a credential.
# The Burp scan report and the Qualys reports are attached to the submission
# directly rather than stored here, because a Burp report contains full request
# and response bodies from an authenticated session.
*.html
*.burp
burp-*
qualys-*
