It’s trust less in the sense that commits can’t be easily forged and are signed with cryptographic keys and identities.
I'm pretty sure being able to verify that the person responsible for a push is an actual maintainer is the opposite of trustless.