what we read
from npm: the package's public record, which is the same document anyone can fetch from the registry. From GitHub: your login and avatar, your verified email addresses, and your permission on the one repository you ask us to check.
- read-only, through the official apis
- no private repository contents, ever
- figures are shown as returned, or as a dash