Please report vulnerabilities privately through GitHub Security Advisories.
`weavatrix-git` treats every repository byte as untrusted. Parsing is bounded
by explicit object-size, delta-depth, history, tree-depth, and reference-depth
limits. MIDX, commit-graph, Bloom, bitmap, index, reflog, cache, and backend
expansion are bounded too. The crate never executes hooks, filters, aliases,
credential helpers, or repository-provided commands.