You should create and use a minimally privileged service account to run your GKE cluster instead of using the Compute Engine default service account.
Service accounts with wide permissions can increase the risk of compromise
Use limited permissions for service accounts to be effective
The following example will fail the google-gke-use-service-account check.
The following example will pass the google-gke-use-service-account check.