Unweighted signal values, each between zero and one.
Deduplicated paths that justify contribution and ownership signals.
Changed path → history path; exposes parent-directory proxies.
API origin, such as https://api.github.com; excludes the API path.
Provider-assigned account ID, represented as a string.
Hosting platform; combine with host and ID when comparing identities.
Weighted sum of the normalized signals, between zero and one.
Provider-linked login; display names are never identity evidence.
A ranked reviewer and the evidence explaining their score.