GitHub branch protection should be set to require signed commits.
You can do this by setting the require_signed_commits attribute to ’true'.
Commits may not be verified and signed as coming from a trusted developer
Follow the appropriate remediation steps below to resolve the issue.