At the last Build WG meeting, we decided to add such a checkbox.
It should be fairly uncontroversial, but in case anyone wants to provide feedback here's the text that I would add:
[ ] I have reviewed *the latest version of* these changes and I am sure that they don’t contain any code that could compromise the security of the CI infrastructure.