So many security breaches involve Linux in one way or another. Your argument doesn't really work.
Meanwhile, for a software business, Github is a wide and deep attack vector and nobody seems to be concerned about it.
Of course the same can be said about any other public git hosting, especially if it combines CI/CD, artifact distribution, identity and trust management.