Previously lohr was unusable in a production setting, anyone could forge
a malicious webhook and either:
- mirror a private repo of yours to another remote they own
- wipe a repo of yours by forcing mirroring from an empty mirror
This is no longer the case!