Ultimately, your weakest point ends up being humans who are prone to mistakes. You can mitigate some of those mistakes with technology but you can't mitigate all of them. So SaaS may help shore up certain attack vectors but it may increase focus on the remaining vectors and may potentially make failure points more significant (more impact for a security breach from a large provider vs less impact of a security breach from systems of independent providers). Some of that can be mitigated with smart designs, but you lose some advantage of traditional "security through obscurity" which has some value (though it shouldn't be relied on as a failsafe).
Those are only somewhat aligned, as anyone with a dispute about terms of service can tell you.
> which can be a bit much for one person who's self-hosting
If your repo serves one person, why do you need your repo to be hosted in public at all? `git init` and a backup are all you need.