git fsck makes it much harder to attack a git repo, but it seems that the normal git workflow does not enable it by default. In it is enabled for all fetches in our config:

But I still can't find a clear answer about what checks does by default. Anyone know?

