Git lets you rewrite history. And I can easily modify the files on GitHub to show that actually I own all your money.
Also, I can make a PR that says that Joe gave me 100$. When Joe in fact did not give me 100$, in fact, Joe doesn't even know me. Yet I can still make a PR for that and how would you know to merge it or not?
Also, I can make a PR where I have 0$, but I transfer 10000$ from myself to Barbara. What is there to stop it? You could just go and accept my patch and I just created money that didn't exist.
Another example is I can have 10000$ and make 10 PRs all showing that I am transferring that 10k to a different person. You merge them all, and now with only 10k I managed to transfer 100k.
Etc.
Basically it's just insufficient in many many ways.
Blockchain requires everything to be cryptographically signed. In a blockchain, each dollar is cryptographically accounted for. Each person is cryptographically accounted for. And the whole system is redundant so that if you temper with one repo it doesn't matter, you need to temper with the majority of them.
Edit: And to your other question. If someone forces you to transfer your coins from your wallet to theirs, you got your coins stolen. Currently most cryptocurrency are designed to be anonymous. In that case, you're screwed. But there could be non-anonymous cryptocurrencies. Those would allow to track criminals much more effectively as it be difficult for them to hide the trail of money. Even in the anonymous case though, if there were processes around this, the network could decide okay this transaction was fraudulent, we agree, and the money trail would all be there, so it could choose to correct it, reinstitute you the fund, do charge backs, or whatever else it wants. That would be much harder with real cash, because the cash is gone, even if you say yup your cash was stolen, nobody knows where it is now. With crypto you'd know where it is, and you'd know which wallet stole it from yours. So that's already a little better.
For example, you could imagine that you'd have say 24h to claim a fraudulent transaction, as soon as you do, all stolen funds could be frozen in the entire network for 14 day, where an investigation would take place. Etc. The technology opens up this kind of things.