I have often wondered this myself. Considering if github was ever compromised, could an attacker modify your source code without your knowledge. Seems like a holy grail of attacks.
What would be interesting if there was some at-rest encryption and maybe some audit functionality.