And of course the signature means "this user can push to github" and nothing more.
Otherwise I don't get it.
But my CI can download and run code from everywhere, so that doesn't mean that I can know what is being uploaded just looking at the git repository alone.