Trusting a forced push w/o any other verification means nefarious history changes can be slipped in.
You can still verify the contents - the content blobs don’t change after the migration. Not sure if there’s a practical attack one could do but maybe
Semi-relevant-ish: https://blog.citp.princeton.edu/2013/10/09/the-linux-backdoo...