The whole "anyone can submit a PR" thing has been a UX issue from day one. That probably needs to go away, and I doubt anyone would really miss it. Where Github could help is by providing a means to build trust that doesn't involve random unknown people slinging code at projects.
Any sort of trust requirement would break the entire model and cause some serious inequality.
How would a random kid in a 3rd world country ever get noticed enough to enter a trust circle, for example?