<?xml version="1.0" encoding="UTF-8"?>
<!--
  GovPulse sitemap.

  ONE entry, and that is still not an oversight — though the reason changed.

  It USED to be a technical impossibility: the app was hash-routed, every
  destination lived behind a `#`, and a fragment is never sent to the server, so
  no crawler could fetch any of them as a distinct page. Clean URLs
  (usePathUrlStrategy + the rewrite in vercel.json) removed that constraint —
  /login and /guest are now real, fetchable URLs.

  They are still not listed, and now that is an editorial choice. Everything
  past the landing page is either a sign-in form or a signed-in surface, and a
  crawler sees both as an empty shell because the app renders into a canvas.
  Listing them would spend crawl budget on pages with nothing to index and
  invite a search result that drops a stranger onto a login form.

  /scan/<token> is the one route that MUST never appear here: each URL carries a
  single-use token for one specific endorsement. robots.txt disallows the prefix
  outright.
-->
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://gov-pulse-rose.vercel.app/</loc>
    <changefreq>monthly</changefreq>
    <priority>1.0</priority>
  </url>
</urlset>
