If someone has access to write to a repo you are downloading code from, and you don't trust that someone, you shouldn't be running the code in that repo.
The only "security" vulnerability is: I have audited and verified that the code in commit 05682ab36ca. And I will use only that version.
What you do then is: download that commit and store it in a local repo, and package it so you can distribute it to your clients.
Auditing external software is tremendous effort, even if it is open source. Using your local repo instead of downloading that commit from GitHub every time is very little extra effort in comparison.
And if you really need it. You can always hash with sha256 yourself and verify that the commit with that sha1 still produces the same sh256. So you can keep downloading it each time, just need to store the sha256.