Skip to content

chore: bring the contribution policy to main ahead of the v2.0.0 merge - #4939

Merged
cliffhall merged 4 commits into
mainfrom
v2/chore/4938-contribution-policy-to-main
Oct 4, 2026
Merged

cliffhall merged 4 commits into
mainfrom
v2/chore/4938-contribution-policy-to-main

Conversation

@cliffhall

Copy link
Copy Markdown
Member

Closes #4938

This PR targets main on purpose. It is a one-time exception to the rule that only a milestone's merge PR targets main, by maintainer decision (@cliffhall), recorded on #4938. AGENTS.md is not changed. Nothing is released: no GitHub Release is published, so release.yml does not run.

Description

Brings the "issues, not PRs" contribution policy (decided on #4861, written in #4869) to the default branch, so that external pull requests can be turned off in the repository settings without leaving main telling contributors to open PRs.

Five files, each byte-identical to v2/main, and nothing else:

  • CONTRIBUTING.md
  • .github/pull_request_template.md
  • .github/ISSUE_TEMPLATE/1-bug_report.yml
  • .github/ISSUE_TEMPLATE/2-feature_request.yml
  • .github/ISSUE_TEMPLATE/config.yml

Issue forms are served from the default branch, so the forms and the config.yml routing (security, new servers) go live when this merges.

Known gap

CONTRIBUTING.md links to three files that do not exist on main until the v2.0.0 milestone merge: AGENTS.md, docs/quality-gate.md and .changeset/README.md. They 404 until then. They are not rewritten here, because a main-only edit would make the file differ from v2/main's and conflict in the milestone merge.

Server Details

  • Server: none (repository-wide)
  • Changes to: contribution docs, PR template, issue forms

Motivation and Context

See #4938.

How Has This Been Tested?

No client-observable surface, so targeted probes instead. npm run local:gate does not exist on main (the gate arrives with the v2.0.0 merge), so it could not be run on this branch; no code, package or workflow file is touched.

  1. Identical to v2/main: git diff --quiet origin/v2/main -- CONTRIBUTING.md .github/pull_request_template.md .github/ISSUE_TEMPLATE exits 0 on this branch.
  2. The milestone merge is unaffected: a trial git merge --no-ff origin/v2/main onto this branch is clean, and the merged tree hash equals origin/v2/main^{tree}.
  3. The forms parse: all three .github/ISSUE_TEMPLATE/*.yml files load as YAML with the expected top-level keys (name, description, labels, body; blank_issues_enabled, contact_links).
  4. Links: the relative links in the two Markdown files were resolved against this branch; CODE_OF_CONDUCT.md and RELEASING.md resolve, the three under Known gap do not.

Breaking Changes

None for users of the servers. Contributors: pull requests are opened by maintainers only; everyone else files an issue.

Types of changes

  • Documentation update

Checklist

  • I have read the MCP Protocol Documentation (not applicable: no protocol surface)
  • My changes follows MCP security best practices (not applicable: docs and forms only)
  • I have updated the server's README accordingly (not applicable: no server change)
  • I have tested this with an LLM client (not applicable: see the probes above)

After merge

A maintainer restricts pull request creation in the repository settings by hand.

🤖 Generated with Claude Code

CONTRIBUTING.md, the PR template and the issue forms, byte-identical to
v2/main, so the default branch states the issues-not-PRs policy before
external pull requests are turned off. Nothing else changes and nothing
is released.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Copilot AI balanced review requested due to automatic review settings October 1, 2026 13:59
@cliffhall cliffhall added the v2 label Oct 1, 2026
@changeset-bot

changeset-bot Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: a207787

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Four passages incorrectly say the forms await a milestone merge, while this PR makes them live on main immediately.

Review effort: Balanced
Findings: 4 Low severity

Open (4)
What changed in this PR

Updates repository-wide contribution guidance to enforce an issues-only workflow ahead of v2.0.0.

Changes:

  • Replaces contribution guidance with the issues-only policy.
  • Adds bug and feature issue forms with routing configuration.
  • Updates the pull request template for maintainers.
File Description
CONTRIBUTING.md Documents the contribution policy and issue workflow.
.github/​pull_request_template.md Adds the issues-only notice and maintainer checklist.
.github/​ISSUE_TEMPLATE/​config.yml Configures issue routing and disables blank issues.
.github/​ISSUE_TEMPLATE/​1-bug_report.yml Adds the structured bug-report form.
.github/​ISSUE_TEMPLATE/​2-feature_request.yml Adds the structured feature-request form.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/ISSUE_TEMPLATE/1-bug_report.yml
Comment thread .github/ISSUE_TEMPLATE/2-feature_request.yml
Comment thread .github/ISSUE_TEMPLATE/config.yml
Comment thread CONTRIBUTING.md Outdated
@cliffhall

Copy link
Copy Markdown
Member Author

Copilot round 1: 4 findings, all declined, nothing pushed. The loop ends here on the "out of scope only" exit.

The constraint behind all four: every file in this PR is byte-identical to v2/main, so the milestone merge stays a pure merge.

Takes CONTRIBUTING.md from v2/main, which dropped the transitional
blank-issue fallback (#4940), so this branch stays byte-identical to
v2/main and main does not receive the stale sentence.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Copilot AI balanced review requested due to automatic review settings October 4, 2026 03:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

All five files match v2/main, and the documentation and forms consistently implement the intended policy.

Review effort: Balanced
Findings: None

Resolved since last review (4)

Takes .github/pull_request_template.md from v2/main, which reduced it to
the issues-not-PRs banner (#4960), so this branch stays byte-identical
to v2/main.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The documentation and forms are internally consistent, validly structured, and byte-identical to their v2/main counterparts.

Review effort: Balanced
Findings: None

Takes .github/ISSUE_TEMPLATE/1-bug_report.yml from v2/main, whose
Server version placeholder now shows both version schemes (#4964), so
this branch stays byte-identical to v2/main.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Copilot AI balanced review requested due to automatic review settings October 4, 2026 03:59
@cliffhall
cliffhall merged commit 5abed86 into main Oct 4, 2026
37 checks passed
@cliffhall
cliffhall deleted the v2/chore/4938-contribution-policy-to-main branch October 4, 2026 04:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Conflicting README guidance, deprecated Roots recommendations, and missing prompt-redaction warnings should be addressed.

Review effort: Balanced
Findings: None

Previously missed (5)

In code that hasn't changed since last review

Medium severity Update README contributor guidance to use issue forms

CONTRIBUTING.md:9

The repository-wide statement remains contradicted by src/fetch/README.md:241 and src/time/README.md:293, both of which explicitly say “Pull requests are welcome.” Because this PR’s stated goal is to stop main from directing contributors to open PRs before that route is disabled, those user-facing pages leave the same contradiction in place. Update them to direct contributors to the issue forms as part of this rollout.

This issue also appears on line 109 of the same file.

Low severity Add sensitive-content warning to prompt field

.github/​ISSUE_TEMPLATE/​1-bug_report.yml:192

This field asks users to publish exact prompts but, unlike the configuration and log fields, does not warn them to remove sensitive content first. Prompts can contain credentials, private paths, proprietary snippets, or personal data; add explicit redaction guidance.

Low severity Replace deprecated Roots preference in request guidance

.github/​ISSUE_TEMPLATE/​2-feature_request.yml:30

Roots is deprecated in the current MCP specification, yet this form says requests demonstrating it are favored. Replace it with a non-deprecated feature or limit this guidance to legacy-era requests.

Low severity Warn users to redact sensitive prompt content

.github/​ISSUE_TEMPLATE/​2-feature_request.yml:123

This field asks users to publish exact prompts without warning them to remove sensitive content first. Prompts can contain credentials, private paths, proprietary snippets, or personal data; add explicit redaction guidance.

Low severity Remove deprecated Roots showcase recommendation

CONTRIBUTING.md:79

The current MCP 2026-07-28 specification deprecates Roots and says new implementations should not adopt it, so this guide should not present adding Roots support as a desired showcase enhancement. Use a non-deprecated example or explicitly qualify Roots work as legacy-only.

spritstarx Bot pushed a commit to SpritStarX/servers that referenced this pull request Oct 11, 2026
The issue forms reach main with modelcontextprotocol#4939, and config.yml sets
blank_issues_enabled: false, so "until then, open a blank issue"
describes a state that no longer exists and recommends a fallback that
is unavailable. State the steady-state rule instead: a change to the
forms goes live at the next milestone merge.

Closes modelcontextprotocol#4940

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
spritstarx Bot pushed a commit to SpritStarX/servers that referenced this pull request Oct 11, 2026
Pull requests are turned off once modelcontextprotocol#4939 lands on main, so the template's
only job is the notice that turns outside PRs away. Drop the policy
comment, which duplicated the banner, and the maintainers' body skeleton
and checklist. The sections and the full checklist move to pr-flow step
6, and AGENTS.md's checklist rule, tree entry and version-PR exception
point there instead of at the template.

Closes modelcontextprotocol#4960

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
spritstarx Bot pushed a commit to SpritStarX/servers that referenced this pull request Oct 11, 2026
The issue forms reach main with modelcontextprotocol#4939 and config.yml disables blank
issues, so "until then the chooser offers a blank issue" goes stale.
State the steady-state rule instead, as CONTRIBUTING.md now does.

Closes modelcontextprotocol#4962

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
spritstarx Bot pushed a commit to SpritStarX/servers that referenced this pull request Oct 11, 2026
Pull request creation was restricted in the repository settings on
2026-10-04, once the policy reached main (modelcontextprotocol#4939). The section still said
nothing stopped new outside PRs and listed automatic closing as an open
decision. Record the setting, and what triage still handles: the open
backlog and PRs from accounts with access that are not maintainers.

Closes modelcontextprotocol#4966

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: cliffhall <cliff@futurescale.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bring the contribution policy (CONTRIBUTING.md, PR template, issue forms) to main ahead of the v2.0.0 merge

2 participants