From a very cursory skim, I get the feeling that this would only work on public repositories where pull requests are allowed, correct?
Not to minimize the issue, as that type of situation is likely the norm on GitHub.
Another way of phrasing what I mean: private repositories are unlikely to be affected by this correct? Since the spoofer would have no way to propose the threatening pull request, only the real dependabot would have permission to do that in that case.