I am not sure if this is the place to do it, but I have a feature request/idea for GitHub.
Request: Add a section for project attribution similar to how the license of the repo is displayed. The attribution should also be retrievable via the API.
In evaluating compliance tools and generating bill of materials and disclosure generation, several open source compliance tools struggle with extracting attribution and copyright. If there were a specific place where the project copyright info was located/ if retrievable via API, compliance tools will have an easier time extracting attribution and selecting which copyright notice is the correct one for the project.
Alternative: Best Practice additions
Alternatively, this conversation can steer in a different direction. I can also see best practice creating an ATTRIBUTION file similar to LICENSE or NOTICE. Or even to have all projects have NOTICE. Looking forward to the conversation.