If one manages to hack on repository one can modify it enormous amount of
ways, including spoofing on SHA (providing wrong contents for it - does
git verify that when getting a pack?), utilizing bugs in git etc...
I doubt somebody would spend that much of an effort but you know,
you can not be paranoid *enough* :)
regards,
Fedor.
--
To unsubscribe from this list: send the line "unsubscribe git" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html