Thanks for responding Nat. My interpretation from the PR:
You've stopped using cookies as a mechanism for marketing/tracking. But you're still doing it by other means.
Rationale:
1. You are still tracking and may share the data with 3rd parties. Justification: privacy statement [0] line 147. It states that data are "aggregated, non-personally identified" which might mean it's GDPR compliant. OTOH: you're presumably holding the non-aggregated data for aggregation purposes in the first place. IANAL but I think that needs consent. I don't know CCPA well enough to comment.
2. The sub-processors statement [2] says this includes Google (and Google Analytics specifically), LinkedIn and Eloqua (marketing analytics firm) among others.
3. Cookies and - possibly? - other client-side technologies are only used for running and improving the service. Justification: Line 238 in the privacy statement. (There's a typo in there btw: "complie" should be "compile" I think).
3. You respect DNT - line 244. Which, presumably, means you do not track user behaviour on any sites other than github? i.e. those in which you are a 3rd party.
4. However, the privacy statement line 31 [1] states: "GitHub may also collect User Personal Information from third parties." Interpretation: whilst you're not collecting 3rd party personal information using cookies, you are (or "may") do so through other means.
[0]: https://github.com/github/site-policy/pull/336/commits/fe1b6...
--
EDIT: clarified GDPR point.
[1]: https://github.com/github/site-policy/pull/336/commits/79a99...
[2]: https://github.com/github/site-policy/pull/336/commits/e98e3...