I'm sure you guys have thought of this but just in case why not make it so you can only do security checks if the company validates its ownership of the domain, server, and GitHub? This way we can all start hardening our software for the impending hack apocalypse. I have many more good ideas like this if you want to hire me. LOL