I am sorry, to enroll a primary maintainers need to open a Pull Request with a Yaml file containing their email address?
And people do that? Here is an example PR: https://github.com/anthropics/oss-scanner/pull/139/changes
Did Anthropic just created a largest ever publicly available collection of email addresses of primary maintainers of OSS projects matching this criteria
established projects that have a critical impact on infrastructure and user security
(Quote from Anthropic)
Is it an invitation for every bad actor to scrape pull requests of this single repo, extract email addresses and target those with every fishing/hacking/account takeover attack imaginable?
Is not that insane?