At the moment only users and teams can be added to restriction rules in branch protection, for example in "Restrict who can dismiss pull request reviews". In order to stay up to date with GitHub REST API, also apps entities should be added to that list.