Repository navigation
go-live 6/9: restrict PRs to collaborators; CONTRIBUTORS.md + SECURITY.md #1820
Description
Activity
- changed the title
[-]go-live 6/9: triage and bulk-close the v1 backlog[/-][+]go-live 7/9: restrict PRs to collaborators; CONTRIBUTORS.md + SECURITY.md[/+]on Jul 27, 2026 Setting flipped — and what "Collaborators only" actually resolves to here
Settings → Features → Pull requests → Collaborators only is now on. External pull requests are closed; the PR tab stays visible and anyone can still read and comment, and Issues are unaffected.
⚠️ It is broader than "the maintainer team"§9 flagged this as worth confirming, and the answer matters:
Count Accounts with push access 110 …of those, direct collaborators 0 …outside collaborators 0 Accounts with admin 30 All 110 are org-inherited — not one is explicitly added to this repository. So the setting restricts PRs to everyone with org-wide base write on
modelcontextprotocol, not to the people who maintain the Inspector.That is still worth having: it closes the public drive-by firehose, which is the actual goal. But the mental model should be "org members only", not "us only", and it is not a substitute for review discipline — a PR from any of those 110 still lands in the same queue.
If tighter control is ever wanted, that is an org-level base-permission change (or an explicit collaborator list on this repo), not a repository PR setting. Out of scope here; noting it so the limitation is recorded rather than assumed away.
Ordering change
Phases 6 and 7 were swapped relative to the plan: this one ran first so the door is shut before the backlog triage in #1819, rather than triaging while new external PRs keep arriving.
Prerequisite status
CONTRIBUTORS.md— ✅ present onmain(survived the v2 tree swap).SECURITY.md—⚠️ was missing. It existed on the pre-swapmainand still exists onv1/main, but the v2 tree never had one, so go-live 4/9: replace main's tree with v2 #1817 silently dropped it. Restored in docs: restore SECURITY.md, lost in the v2 tree swap #1843 with the supported-versions table this issue asks for, plus an explicit carve-out that the no-outside-PRs policy does not apply to security reports — without that, closing the PR path reads as "no way to reach us".- Private vulnerability reporting — ✅ verified enabled (
GET /repos/.../private-vulnerability-reporting→{"enabled": true}), so the advisory route inSECURITY.mdworks. - Issue templates — ❌ still absent. Additive and lower urgency now that the two policy docs are in place; remaining work for this issue.
- changed the title
[-]go-live 7/9: restrict PRs to collaborators; CONTRIBUTORS.md + SECURITY.md[/-][+]go-live 6/9: restrict PRs to collaborators; CONTRIBUTORS.md + SECURITY.md[/+]on Jul 28, 2026 - added a commit that references this issue
on Jul 28, 2026 Phase 6 complete.
Task State Docs landed first ✅ CONTRIBUTORS.md(survived the tree swap) +SECURITY.md(#1843)Confirm what "collaborator" resolves to ✅ 110 accounts, all org-inherited, 0 direct — see the comment above Flip PRs → Collaborators only ✅ done SECURITY.md+ private reporting✅ #1843; private vulnerability reporting verified enabled Issue templates ➡️ split out to #1844 The main finding:
SECURITY.mdwas missing frommain. It existed on the pre-swapmain(ac3c1a12) and still exists onv1/main, but the v2 tree never had one — so #1817 silently dropped the security policy from the default branch, and nothing alerted on it.That mattered because of the timing: the security-report route disappeared in the same window as external pull requests being closed. Restored in #1843 with the supported-versions table, plus an explicit carve-out that the no-outside-PRs policy does not apply to security reports — without which the new model reads as "no way to reach us".
Issue templates are the one remaining task and are tracked separately in #1844. They are additive: the policy docs are in place, so a contributor who looks will find the explanation. Templates put it in front of them at the moment they try to contribute, which is worth doing but does not block this phase.
Phases 6 and 7 were swapped from the original plan — this ran ahead of #1819 so the door is shut before triaging 125 open PRs.
- added a commit that references this issue
on Aug 1, 2026
Phase 6 of 9 in the v2 go-live runbook — see #1804 (§9). Reversible (one click).
Move to the issues-only contribution model.
Tasks
CONTRIBUTORS.md(Add CONTRIBUTORS.md: issues-only policy (share prompts, not PRs) #1517) and issue templates. The setting below gives a contributor no explanation; they just find no "Create pull request" button.gh api repos/modelcontextprotocol/inspector/collaborators --jq '.[] | select(.permissions.push) | .login'SECURITY.md: supported-versions table (v2 supported, v1 security fixes only, <1.0.0 unsupported) and private reporting enabled.Fold into #1517 rather than duplicating it.
Docs · changelog