Merge pull request #252 from MarkLodato/typosquatting

Explain how SLSA can help with typosquatting.
*Threat:* Register a package name that is similar looking to a popular package
and get users to use your malicious package instead of the benign one.
*Mitigation:* **Mostly outside the scope of SLSA.** That said, the requirement
to make the source available can be a mild deterrent, can aid investigation or
ad-hoc analysis, and can complement source-based typosquatting solutions.
<sup>[[Verified history] and [Retained indefinitely] @ SLSA 3]</sup>
