"If we create a fake issue that's clearly ridiculous β like, 'add a feature to play music on toaster ovens' β the bots will likely respond to it. We can then use that as a signal to identify and block their accounts."
"I think I have an idea. What if we create a 'canary' issue, something that's obviously fake, but looks legitimate enough to lure the bots in?" spotify block github
A secondary issue involves OAuth authentication flows. Developers hosting applications on GitHub Pages are encountering strict CORS (Cross-Origin Resource Sharing) and Redirect URI validations. "If we create a fake issue that's clearly