Safe operating model
- grant only the repository permissions required by the integration;
- review the repository and branch before importing or mirroring;
- treat webhooks as authenticated events and verify their signatures;
- keep deployment and provider secrets in P2HS configuration, not committed files;
- review generated changes before production deployment.

