Why is it risky?
I followed your link, which said that projects can self-host. True. Oracle can self-host if they want to. Should they want to?
I followed your link in that one, which says you should self-host to avoid GitHub-related downtime. So does the next link in the recursive trail, and most of the ones in there. It's true that if you aren't on GitHub, you'll avoid GitHub-related downtime - but how much downtime will your alternative incur, and what is the cost of the staffing needed to reach that point? And what is the downside of being unable to access GitHub briefly for a project like this, such that it becomes worth investing in that staffing?
There's this reply to your comment that I see you didn't reply to: https://news.ycombinator.com/item?id=23818307
> I used to help maintain Xfce's svn and then git server. I'm not going to say it was hard, but it was work, and it was work that took time (time that was volunteer free time) away from working on Xfce itself. [...] That was a foolish attitude that took time away from the actual goal, which was making Xfce better.
I will certainly agree that you should not host your primary website on GitHub; there are services that are designed for reliable website hosting. For something like Java, I'd also say you shouldn't host your releases on GitHub. But Oracle Java remains on Oracle's website, and OpenJDK binaries aren't hosted on GitHub - AdoptOpenJDK's website is behind Cloudflare.
I do also think people should have a strategy for moving off their code hosting provider, including making backups of things like issues/pull requests. But that applies even if (perhaps especially if) you self-host, and I don't know anyone who actually does that, regardless of provider. If you're just interested in the code itself, the nice thing about git is that every developer's laptop is an effective backup, so you can put off figuring out a business continuity plan until an actual problem arises.
A few links in (https://news.ycombinator.com/item?id=23102942), you seem to claim that GitHub is insecure because Microsoft's org account was "hacked". It turns out that one account belonging to an MS employee who was a member of that org was broken into https://www.zdnet.com/article/hacker-gains-access-to-a-small... . That risk doesn't seem particularly fundamentally different with self-hosting, since the attack was on the user account, not the service itself.
One link beyond that (https://news.ycombinator.com/item?id=23057769), you point out that you'd need to trust GitHub not to snoop on your private data, which is true, but irrelevant in this context.
Let me be clear - I am not an advocate of moving things to "the cloud" / hosted services for its own sake, and in fact, I believe that most of the time, people are better-served by putting a couple of servers in colo than by using some public cloud service. (My own employer runs an internal GitLab instance and spends a decent bit of staff time on keeping it operational and upgraded, and I think that's a great idea for us and for our needs!) But that's because I believe it's actually better for them to do so. I don't see the argument that people are actually better off running their own git hosting for open-source projects, in general.