I realized there is one benefit that this offers: Github attests to the time that it happened.
Supposing you're looking at a popular repository, one where a malicious commit would likely be noticed eventually. The last commit was "one month ago". What's to say someone didn't compromise the developer's computer, sign a malicious commit backdated by a month, and push it to Github? If the last commit was made via the Github UI, you have pretty good assurance (i.e. as much as you trust Github not to get hacked) that this didn't happen.
Even better if the previous commit was done by the author, and the Github UI commit is trivially confirmed as safe. That way, you can confirm the author's commit locally, in case Github is the one that got hacked.
If both the author and Github got hacked, :shrug: I guess that's a pretty skilled adversary.
Caveat: All of the above is my own analysis. I'm curious if there are flaws in my thinking here.