Sign outbound approval webhook payloads with an HMAC (shared secret from helio.yaml) and
send it in a header so receivers can verify authenticity. Document the verification recipe.
Good first issue: contained to the webhook notifier; clear acceptance criteria.
Sign outbound approval webhook payloads with an HMAC (shared secret from
helio.yaml) andsend it in a header so receivers can verify authenticity. Document the verification recipe.
Good first issue: contained to the webhook notifier; clear acceptance criteria.