I get the mentality but it feels very much like security through obscurity. When did we decide that that was the correct model?
This is not security via obscurity; it is reducing your attack surface as much as possible.
hey cofounder here. since it takes my 16 year old neighbors son 15 mins and $100 claude code credits to hack your open source project
Security through obscurity is only problematic if that is the only, or a primary, layer of defense. As an incremental layer of deterrence or delay, it is an absolutely valid tactic. (Note, not commenting on whether that is the rationale here.)