Such items should have a red banner: CAUTION, unofficial, use at your own risk. The other approach is like Docker hub has "docker official image" for popular ones.
Also as long as you don’t use it to curl random things the security impact is not that high and I doubt that there a tons of uses for that.. you probably won’t attack yourself?
Trademarks seem like a sore spot for successful OSS but probably useful for solving this problem.
Or perhaps a license change? Might be tricky to do what the author means and still meet the definition of /open/. Maybe that's ok?
Uh-huh, and what makes that any different if someone else is doing it?
This feels like someone who discovered package managers for the first time.