It's, uh, less than ideal that I'm allowed to claim a GitHub username like this.
You can create pretty convincing pull requests with something like this. Just sayin'.

Got this response from GitHub's vuln program: "Thanks for the submission! As noted on our website, typosquatting is out of scope and ineligible for reward under the GitHub bounty program." (https://bounty.github.com/ineligible#typosquatting)

Fair enough. But I wish something could be done, regardless of the reward.

Ineligible submissions

GitHub Bug Bounty
Worry not, Coplllot is on the case.
And who could forget their trusty sidekick, Dependobat!
However, it's kinda worrying that "copliot", "copllot" etc. were already taken.
@jviide yea, especially since GitHub limits adding dependabot to teams granting direct push rights

@jviide

Imagine using one of the names of the slopmachines like this...

Even if the code is rubbish no one would notice (or check), and the majority would just merge it anyway as long as the tests succeeded.

Also, thanks for making me laugh out loud. And loathe Github even more.

@jviide

This is so bad and yet so hilarious and also so concerning  

Thank you ! :)

@jviide @sten
It would be great if such special accounts would include some form of special marker, e.g. a blue/green/gold/… checkmark.
@jviide "Waiting for Badot"; a supply chain security tragicomedy...
@fuzzyfuzzyfungus @jviide
Brigitte Badot, acting so innocent