Security Fixes
- Update org.apache.sshd to 2.19.0 This fixes CVE-2026-56624.
- Widen allowed version range to [2.19.0,3.0.0). This allows applications using JGit to update org.apache.sshd to a newer version without us needing to provide an update.
Build and Release Engineering
- Log loose ref deletion during ref cleanup