GitHub hands out your repo visitors IP like candy who ask for it politely
twitter.com
twitter.com
Still doesn't sound too outrageous. At least, it's not unprecedented and is in line with the existing practices of companies responding to law enforcement requests.
I wonder if it's still true. I imagine they have some Content-Security-Policy preventing it so you can't do hacks like embedding an external URL in an SVG.
content-security-policy: default-src 'none'; img-src data:; style-src 'unsafe-inline'