GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
"https://github.com/pypa/advisory-database/blob/main/vulns/gitpython/PYSEC-2023-137.yaml"