The version of `go-git` that you are on is vulnerable to [CVE-2023-1732](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1732) and has since been [patched](https://github.com/go-git/go-git/releases/tag/v5.7.0)