Okay, so say I submit a pull request for a phishing domain pretending to be an alias of something, and months/years later trick you into visiting it. Seems risky to me.
This would only be risky if I got phished into visiting your phishy domain AND was stupid enough to consciously want to enter a password into it, in which case the risks are the same as if I used a human-memorized password.
My password "manager" doesn't automatically fill in passwords until I consciously ask it to.
But some amount of human oversight over those pull requests would be in order.