When the github secret is provided, payloads should be validated against the hash signature available in the HTTP header X-Hub-Signature