This tool parses local source trees and invokes Git in those repositories. It does not intentionally execute or import analyzed Python code. Run it only on source and Git repositories you trust, and review CI checkout permissions as you would for any source-analysis job.
Do not attach credentials, private repository contents or unredacted local paths to public issues. For a security-sensitive report, use GitHub's private vulnerability reporting for this repository when available.
Only the latest main revision is maintained before the first tagged stable release.