Yes but SHA1 collisions are easy enough to engineer, so even then compromise is probably possible.
(I don't know how hard it is to push a different object to an existing SHA on GitHub—I'm guessing that you probably have to remove all references to the original object at that SHA?)