Standardizing on one external code hosting solution (GitHub) instead of a community managed one is not a solution.

No, but it is equivalent of autoexec.bat like functionality. You can use it for many many things like viruses propagation, content control and even it is helpful for users ! ;)

It's just like giving external users self-modifing code access - asm, lisp, js - let's they upload it and we execute ;)

#DONOTSENDCODE Manifesto, where ?