http://felixge.de/2013/03/11/the-pull-request-hack.html
> Whenever somebody sends you a pull request, give them commit access to your project.
I agree with requiring more accountability before granting the ability to create official releases.