I feel the same way about those bots that tell you about insignificant security vulnerabilities in some project you abandoned. It's basically spam.
That said, this does seem like it is a bit more useful. As long as they actually read the changes and make sure they aren't false positives. Which I'm guessing they didn't do for 666 repos.