Records the negative space for #818: why no auto GITEA_TOKEN, why two
tokens not one, why digest-pin on the Renovate action, OSV-vs-platform
distinction on self-hosted Gitea, why the weekly schedule does not mute
security PRs, why lockFileMaintenance has no automerge, and why there is
no l2-containers.puml entry.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>