Skip to content

go-live 6/9: restrict PRs to collaborators; CONTRIBUTORS.md + SECURITY.md #1820

Description

@cliffhall

Phase 6 of 9 in the v2 go-live runbook — see #1804 (§9). Reversible (one click).

Note: this was originally planned as phase 7. It was moved ahead of the v1 backlog triage (#1819, now phase 7) so external pull requests are closed before triaging 125 open PRs, rather than triaging while new ones keep arriving.

Move to the issues-only contribution model.

Tasks

  • Land the docs first — CONTRIBUTORS.md (Add CONTRIBUTORS.md: issues-only policy (share prompts, not PRs) #1517) and issue templates. The setting below gives a contributor no explanation; they just find no "Create pull request" button.
  • Confirm what "collaborator" resolves to here — write/maintain/admin on the repo, which may include org-wide base write rather than just the maintainer team:
    gh api repos/modelcontextprotocol/inspector/collaborators --jq '.[] | select(.permissions.push) | .login'
  • Flip Settings → Features → Pull requests → "Collaborators only". PR tab stays visible, anyone can read and comment, only write-access users can open new PRs. Issues unaffected.
  • SECURITY.md: supported-versions table (v2 supported, v1 security fixes only, <1.0.0 unsupported) and private reporting enabled.

Fold into #1517 rather than duplicating it.

Docs · changelog

Activity

  1. self-assigned this
    on Jul 27, 2026
  2. changed the title [-]go-live 6/9: triage and bulk-close the v1 backlog[/-] [+]go-live 7/9: restrict PRs to collaborators; CONTRIBUTORS.md + SECURITY.md[/+] on Jul 27, 2026
  3. cliffhall commented on Jul 28, 2026

    @cliffhall
    MemberAuthor

    Setting flipped — and what "Collaborators only" actually resolves to here

    Settings → Features → Pull requests → Collaborators only is now on. External pull requests are closed; the PR tab stays visible and anyone can still read and comment, and Issues are unaffected.

    ⚠️ It is broader than "the maintainer team"

    §9 flagged this as worth confirming, and the answer matters:

    Count
    Accounts with push access 110
    …of those, direct collaborators 0
    …outside collaborators 0
    Accounts with admin 30

    All 110 are org-inherited — not one is explicitly added to this repository. So the setting restricts PRs to everyone with org-wide base write on modelcontextprotocol, not to the people who maintain the Inspector.

    That is still worth having: it closes the public drive-by firehose, which is the actual goal. But the mental model should be "org members only", not "us only", and it is not a substitute for review discipline — a PR from any of those 110 still lands in the same queue.

    If tighter control is ever wanted, that is an org-level base-permission change (or an explicit collaborator list on this repo), not a repository PR setting. Out of scope here; noting it so the limitation is recorded rather than assumed away.

    Ordering change

    Phases 6 and 7 were swapped relative to the plan: this one ran first so the door is shut before the backlog triage in #1819, rather than triaging while new external PRs keep arriving.

    Prerequisite status

    • CONTRIBUTORS.md — ✅ present on main (survived the v2 tree swap).
    • SECURITY.md — ⚠️ was missing. It existed on the pre-swap main and still exists on v1/main, but the v2 tree never had one, so go-live 4/9: replace main's tree with v2 #1817 silently dropped it. Restored in docs: restore SECURITY.md, lost in the v2 tree swap #1843 with the supported-versions table this issue asks for, plus an explicit carve-out that the no-outside-PRs policy does not apply to security reports — without that, closing the PR path reads as "no way to reach us".
    • Private vulnerability reporting — ✅ verified enabled (GET /repos/.../private-vulnerability-reporting → {"enabled": true}), so the advisory route in SECURITY.md works.
    • Issue templates — ❌ still absent. Additive and lower urgency now that the two policy docs are in place; remaining work for this issue.
  4. changed the title [-]go-live 7/9: restrict PRs to collaborators; CONTRIBUTORS.md + SECURITY.md[/-] [+]go-live 6/9: restrict PRs to collaborators; CONTRIBUTORS.md + SECURITY.md[/+] on Jul 28, 2026
  5. cliffhall commented on Jul 28, 2026

    @cliffhall
    MemberAuthor

    Phase 6 complete.

    Task State
    Docs landed first ✅ CONTRIBUTORS.md (survived the tree swap) + SECURITY.md (#1843)
    Confirm what "collaborator" resolves to ✅ 110 accounts, all org-inherited, 0 direct — see the comment above
    Flip PRs → Collaborators only ✅ done
    SECURITY.md + private reporting ✅ #1843; private vulnerability reporting verified enabled
    Issue templates ➡️ split out to #1844

    The main finding: SECURITY.md was missing from main. It existed on the pre-swap main (ac3c1a12) and still exists on v1/main, but the v2 tree never had one — so #1817 silently dropped the security policy from the default branch, and nothing alerted on it.

    That mattered because of the timing: the security-report route disappeared in the same window as external pull requests being closed. Restored in #1843 with the supported-versions table, plus an explicit carve-out that the no-outside-PRs policy does not apply to security reports — without which the new model reads as "no way to reach us".

    Issue templates are the one remaining task and are tracked separately in #1844. They are additive: the policy docs are in place, so a contributor who looks will find the explanation. Templates put it in front of them at the moment they try to contribute, which is worth doing but does not block this phase.

    Phases 6 and 7 were swapped from the original plan — this ran ahead of #1819 so the door is shut before triaging 125 open PRs.

  6. added this to the v2.0.0 milestone on Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

v2Issues and PRs for v2

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions