Sure, and everybody who has read the spec knows that. Alas, that's 1% of your user base.
For the rest of your users it wouldn't hurt to say, "You might see something different if you're logged in." Or if they are logged in, saying, "Were you expecting something different? Maybe you just don't have access yet."
Wait, we cant hold github to account for making linkrot and not applying the spec, but when the spec is implemented by them, for good reason, say "but 1% of your user base reads the spec". Thats a bit of a double standard.
All we need is an error code 402.5 "plausible deniability between unauthorized and not found"...