# Workflow One issue per unit of work, one branch and one PR per issue: - ensure a tracked issue exists with a definition of done - branch from `next` (never from `main`) - do the work; open a PR based on `next` (never on `main`) - pass an independent review, then the change is squash-merged into `next` - push; nothing stays local-only `next` is the branch for the next milestone and must stay green and mergeable to `main` without notice. Only `sneak` merges `next` into `main`, and for now only `sneak` merges into `next`. No commits land directly on `main` or `next` — only merges via PRs. Issue branches do NOT touch this file — it is maintained on `next`. Every branch editing `TODO.md` conflicts with every other. # Status The repository has been brought up to current repo standards: `script/` Scripts to Rule Them All entrypoints with the `Makefile` reduced to thin shims, a `Dockerfile` whose `lint` and `test` phases gate the build, a `.gitea/workflows/` CI workflow running `script/cibuild`, the vendored `.golangci.yml`, `REPO_POLICIES.md`, `.editorconfig`, `.dockerignore`, a `LICENSE` file, and a comprehensive `.gitignore`. Lint is clean under the standard `default: all` configuration, with the findings fixed rather than suppressed. The only annotations are justified `//nolint:gosec` on the `ping`/`curl` subprocess calls (G204) and on opening the operator-chosen log file (G304): fixed argv with no shell, so these are false positives, annotated as the reference repos do. # Next Step Feature work, each on its own branch and PR from `next`: - https://git.eeqj.de/sneak/rtnetmon/issues/2 — macOS support: VPN-aware interface detection and a single-interface UI when only one interface exists. - https://git.eeqj.de/sneak/rtnetmon/issues/3 — show Starlink status lines when Starlink is the non-VPN gateway.