Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
95 commits
Select commit Hold shift + click to select a range
210b1e1
fix(web): only DANGEROUSLY_OMIT_AUTH=true/1 disables /api auth (#2331)
cliffhall Sep 16, 2026
da8c352
feat: per-server setting to suppress the standalone GET notification …
cliffhall Sep 16, 2026
2376420
fix: inline same-document $refs before choosing form widgets (#2321)
cliffhall Sep 16, 2026
b95e60f
fix: stamp Mcp-Method on modern-era notification POSTs (#2385)
cliffhall Sep 16, 2026
bc75602
Merge pull request #2390 from modelcontextprotocol/v2/fix/2331-omit-a…
cliffhall Sep 16, 2026
2b5ddad
fix: decode the whole $ref fragment before splitting; walk legacy dep…
cliffhall Sep 16, 2026
134723e
docs: frame the notification header stamping as a compatibility worka…
cliffhall Sep 16, 2026
956bf13
fix: detach the OIDC compat's normal-path body releases (#2389)
cliffhall Sep 16, 2026
a6ae234
Merge remote-tracking branch 'origin/v2/main' into v2/fix/2389-oidc-d…
cliffhall Sep 16, 2026
0b2402d
Merge remote-tracking branch 'origin/v2/main' into v2/fix/2385-mcp-na…
cliffhall Sep 16, 2026
716d597
Merge pull request #2392 from modelcontextprotocol/v2/fix/2385-mcp-na…
cliffhall Sep 16, 2026
8d682ed
fix: keep constraining $ref siblings, skip embedded resources, bound …
cliffhall Sep 16, 2026
2b6e7ba
Merge pull request #2393 from modelcontextprotocol/v2/fix/2389-oidc-d…
cliffhall Sep 16, 2026
4a447ce
fix: suppress only the endpoint's SSE GET, and scope the setting to t…
cliffhall Sep 16, 2026
091bc36
fix: walk only subschema keywords, bound depth, reject bad escapes, k…
cliffhall Sep 16, 2026
6a54c38
Merge remote-tracking branch 'origin/v2/main' into v2/feat/2317-suppr…
cliffhall Sep 16, 2026
4451a3b
Merge remote-tracking branch 'origin/v2/main' into v2/fix/2321-resolv…
cliffhall Sep 16, 2026
2de7423
Merge pull request #2391 from modelcontextprotocol/v2/fix/2321-resolv…
cliffhall Sep 16, 2026
0958136
Merge pull request #2394 from modelcontextprotocol/v2/feat/2317-suppr…
cliffhall Sep 16, 2026
3d51384
fix(core): reframe type-union as a portability trade, not a defect (#…
cliffhall Sep 16, 2026
0a05f9f
docs: document read-only mcp.json consumption by external tooling (#1…
cliffhall Sep 16, 2026
2ca982c
docs(core): admit the dialect-portability evidence class in schemaLin…
cliffhall Sep 16, 2026
c12adbc
docs: note that the Inspector keeps env and client secrets out of mcp…
cliffhall Sep 16, 2026
ae9c186
test(core): pin the named dialect in the type-union message (#2395 re…
cliffhall Sep 16, 2026
d6d8b8e
docs: scope the secret-stripping note to the catalog fields it covers…
cliffhall Sep 16, 2026
626d1b9
fix(core): caveat the null branch of the type-union suggestion (#2395…
cliffhall Sep 16, 2026
9bab0a7
docs: note the memory secret store keeps existing plaintext in mcp.js…
cliffhall Sep 16, 2026
e9cdf32
docs: clarify the memory-store wording and flag stdio command executi…
cliffhall Sep 16, 2026
ea5e7b3
Merge pull request #2395 from modelcontextprotocol/v2/chore/2286-type…
cliffhall Sep 16, 2026
0e883be
Merge remote-tracking branch 'origin/v2/main' into v2/docs/1912-reado…
cliffhall Sep 16, 2026
66770e1
Merge pull request #2396 from modelcontextprotocol/v2/docs/1912-reado…
cliffhall Sep 16, 2026
3b78545
feat: run skills:eval through the GitHub Copilot CLI (#2397)
cliffhall Sep 16, 2026
4badc53
fix: never score a Copilot turn past the budget from a coalesced chun…
cliffhall Sep 16, 2026
41c9994
Merge branch 'v2/main' into v2/chore/2397-copilot-skills-eval
cliffhall Sep 16, 2026
57f23bc
fix: surface the Copilot sign-in hint, name the agent on the empty ha…
cliffhall Sep 16, 2026
ce20b2e
docs: re-measure the Copilot hand-offs at RUNS=5 and track the pagina…
cliffhall Sep 16, 2026
54608dc
Merge remote-tracking branch 'origin/v2/chore/2397-copilot-skills-eva…
cliffhall Sep 16, 2026
eb44b0d
fix: stop Copilot's whole process group at the turn budget; record us…
cliffhall Sep 16, 2026
54f15c0
fix: stop in-flight Copilot groups when a sample rejects, not only on…
cliffhall Sep 16, 2026
cf6d4b9
docs: re-align the H2 2026 roadmap with the published MCP roadmap (#2…
cliffhall Sep 16, 2026
306a50c
Merge pull request #2398 from modelcontextprotocol/v2/chore/2397-copi…
cliffhall Sep 16, 2026
c0bef16
docs: link the unblocked-work artifact at the top of the roadmap (#2400)
cliffhall Sep 16, 2026
d8a7356
docs(skills): load test-servers before searching on e2e coverage prom…
cliffhall Sep 16, 2026
d701734
docs: account for all five recorded Copilot runs (#2402 review)
cliffhall Sep 16, 2026
41b5a33
Merge branch 'v2/main' into v2/docs/2400-roadmap-realign
cliffhall Sep 16, 2026
298cce3
docs: address Copilot review on the roadmap realignment (#2401 review)
cliffhall Sep 16, 2026
8ce0d7c
Merge pull request #2402 from modelcontextprotocol/v2/chore/2399-copi…
cliffhall Sep 16, 2026
e5494eb
Merge branch 'v2/main' into v2/docs/2400-roadmap-realign
cliffhall Sep 16, 2026
3961bd1
docs: address Copilot round 2 on the roadmap realignment (#2401 review)
cliffhall Sep 16, 2026
9741759
docs: address Copilot round 3 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
a9453bd
docs: address Copilot round 4 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
5157b0a
docs: address Copilot round 5 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
a2430e7
docs: address Copilot round 6 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
2235798
docs: address Copilot round 7 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
1683fa4
docs: address Copilot round 8 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
070fe36
docs: address Copilot round 9 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
1a6df14
docs: address Copilot round 10 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
8be1cd6
docs: address Copilot round 11 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
b4efb47
docs: address Copilot round 12 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
4bc4643
docs: address Copilot round 13 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
85f4ecc
docs: address Copilot round 14 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
d7c1f9f
docs: address Copilot round 15 on the roadmap realignment (#2401 review)
cliffhall Sep 17, 2026
85be2c1
Merge pull request #2401 from modelcontextprotocol/v2/docs/2400-roadm…
cliffhall Sep 18, 2026
8dee4cf
docs: add the security-advisory skill and carve advisory drafts out o…
cliffhall Sep 19, 2026
41efd17
docs: address Copilot review round 1 on #2444
cliffhall Sep 19, 2026
2bba258
docs: address Copilot review round 2 on #2444
cliffhall Sep 19, 2026
b2d44ff
docs: address Copilot review round 3 on #2444
cliffhall Sep 19, 2026
4da164a
docs: address Copilot review round 4 on #2444
cliffhall Sep 19, 2026
856c82f
docs: address Copilot review round 5 on #2444
cliffhall Sep 19, 2026
50a9634
docs: address Copilot review round 6 on #2444
cliffhall Sep 23, 2026
f8b3521
docs: add a secret-storage guide for every runtime (#2447)
cliffhall Sep 23, 2026
c0c2a20
chore: add the project LICENSE and point every manifest at it (#2406)
cliffhall Sep 23, 2026
14cde9e
docs: address Copilot review round 1 on secret-storage guide (#2448)
cliffhall Sep 23, 2026
ccc831c
docs: address Copilot review round 8 on #2444
cliffhall Sep 23, 2026
67b23bd
docs: address Copilot review round 2 on secret-storage guide (#2448)
cliffhall Sep 23, 2026
2b96781
docs: name the lock after the configured secrets file (#2448 review)
cliffhall Sep 23, 2026
15f2d98
Merge pull request #2449 from modelcontextprotocol/v2/chore/2406-license
cliffhall Sep 23, 2026
cc73b5b
feat: MCP_INSPECTOR_SECRET_KEY_FILE, a Docker warning and a threat mo…
cliffhall Sep 23, 2026
bf4beba
fix: treat a blank MCP_INSPECTOR_SECRET_KEY_FILE as a key problem (#2…
cliffhall Sep 23, 2026
d8f8895
docs: loudly call out the plaintext fallback on hosts with no keychai…
cliffhall Sep 23, 2026
8e4cfff
docs: key-file wording, stale comments and a safer Docker key example…
cliffhall Sep 23, 2026
b4af7e4
fix: refuse a key file that is the secrets file itself (#2448 review)
cliffhall Sep 23, 2026
bb83deb
Merge pull request #2444 from modelcontextprotocol/v2/docs/2443-secur…
cliffhall Sep 23, 2026
8a78c74
docs(skills): stop board lookups from trusting item-list --limit (#2451)
cliffhall Sep 23, 2026
15310eb
Merge branch 'v2/main' into v2/docs/2447-secret-storage-guide
cliffhall Sep 23, 2026
9b03435
Merge pull request #2448 from modelcontextprotocol/v2/docs/2447-secre…
cliffhall Sep 23, 2026
eabbfc4
docs(skills): fail closed on a missing ITEM_ID and an incomplete dump…
cliffhall Sep 23, 2026
7dd0362
Merge branch 'v2/main' into v2/fix/2451-board-lookup-limits
cliffhall Sep 23, 2026
4964bb6
docs(skills): name every id a #11 card needs, not just the lookup's (…
cliffhall Sep 23, 2026
68dc5f5
docs(skills): gate the recovery steps on a complete dump (#2452 review)
cliffhall Sep 23, 2026
24b1a12
docs(skills): refuse to re-apply without a usable snapshot (#2452 rev…
cliffhall Sep 23, 2026
de44e97
Merge pull request #2452 from modelcontextprotocol/v2/fix/2451-board-…
cliffhall Sep 23, 2026
f9dba02
chore: bump version to 2.8.0 (#2453)
cliffhall Sep 23, 2026
dcc43ad
Merge pull request #2454 from modelcontextprotocol/v2/chore/2453-bump…
cliffhall Sep 23, 2026
3ad3f72
chore: merge v2/main into main for the v2.8.0 release
cliffhall Sep 23, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
167 changes: 132 additions & 35 deletions .claude/skills/board-ops/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,9 +26,57 @@ The two projects have their own field and option IDs and none of them are
interchangeable — a #28 id passed to #11 is rejected with "option Id does not
belong to the field", so the mistake is at least loud.

## Finding a card without trusting `--limit`

⚠️ **`gh project item-list --limit N` truncates silently.** Past `N` it returns
the first `N` items with no error and no warning, so a `select` over the result
matches nothing and a card that exists reads as missing. Board #28 passed 500
items in September 2026 — double the figure quoted here two months earlier — and
the old `--limit 500` lookups reported a carded issue as unboarded and 16 GHSA
drafts as absent in one session (#2451). A limit is a guess about the board's
size; don't make the recipes depend on it being right.

- **An issue's card is looked up from the issue**, which is independent of board
size — see [Move an existing card](#move-an-existing-card).
- **A draft card or a whole-board dump** (the GHSA lookup, the snapshot, the
recovery dump, `/issue-triage`'s sweep and audit) genuinely needs the full
listing. Those recipes use a limit with headroom **and** compare the result's
`.items | length` against the `.totalCount` that `item-list --format json`
also returns, so a truncated listing fails loudly instead of passing as
complete. The check also catches a failed `gh` call, whose empty output has
neither key. Where a later step reads the dump from a file, an incomplete dump
is deleted, so that step fails on the missing file rather than running on
partial data.

**Only issues go on a board — never PRs, never draft cards.** A PR is tracked
through the card of the issue it closes.

**The one exception is a GitHub security advisory**, tracked by a draft card
titled `[GHSA-xxxx-yyyy-zzzz] - …` because a real issue would disclose it before
a fix exists. The flow is `/security-advisory`.
Comment thread
cliffhall marked this conversation as resolved.

⚠️ **A draft card has no repository and no issue number, so the issue-side
lookup below cannot find one**, and `item-add --url` has no URL to be given.
Look it up by **title** in the full listing instead, then feed that item id to
`item-edit` or `item-delete` exactly as usual:

```sh
GHSA=GHSA-xxxx-yyyy-zzzz # the advisory's real id
ITEM_ID= # never let an earlier lookup's id survive a failed one
BOARD=$(gh project item-list 28 --owner modelcontextprotocol --format json --limit 2000)
if jq -e '(.items | length) == .totalCount' <<<"$BOARD" >/dev/null; then
ITEM_ID=$(jq -r '.items[] | select(.content.type=="DraftIssue")
| select(.content.title | startswith("['"$GHSA"']")) | .id' <<<"$BOARD")
[ -n "$ITEM_ID" ] || echo "no draft card titled [$GHSA] on #28" >&2
else
echo "item-list incomplete or failed — raise --limit; not concluding anything" >&2
fi
```

Match on the **bracketed GHSA id**, not on words from the summary — a summary is
free text and two advisories can share one. Advisory drafts live on #28 only;
`/issue-triage`'s audit reports one found anywhere else.

## V2 board (#28) IDs

The project node id and the field ids are stable. The **option** ids are **not** —
Expand Down Expand Up @@ -123,24 +171,48 @@ gh project item-edit --project-id PVT_kwDOCt2Azc4BA5sz --id "$ITEM_ID" \

### Move an existing card

Look the item id up by issue number rather than re-adding it. Keep `--limit`
above the board's item count (~265 as of 2026-08-01) — past it `item-list`
truncates **silently**, `select` matches nothing, and `item-edit --id ""` fails
with an opaque node-resolution error rather than saying the limit was too low.
Look the item id up **from the issue** rather than re-adding it. An issue's
`projectItems` lists the cards it has on every board, so the lookup does not
depend on how many items the board holds (see [Finding a card without trusting
`--limit`](#finding-a-card-without-trusting---limit)). Select the card by the
board's **node id**, not its number: project numbers are per-owner, and an issue
can also sit on a user-owned project that happens to be numbered 28. Querying
through the repository also means the issue number cannot match another repo's
issue — board #11 really does carry a `modelcontextprotocol/servers` card.

**For a v1 card on #11, swap every #28 id, not just the lookup's.** #11's node
id `PVT_kwDOCt2Azc4BA5sz` goes in both the lookup's `select` and the edit's
`--project-id`; the edit also takes #11's own Status field
`PVTSSF_lADOCt2Azc4BA5szzgzkS-g` and an option id from [its
table](#v1-board-11-ids); and a delete is `item-delete 11`.

The mutation runs only on a non-empty id: `item-edit --id ""` fails with an
opaque node-resolution error rather than saying the card was not found. The
`|| ITEM_ID=` matters too — on a GraphQL error (a number that is a PR, not an
issue; a rate limit) `gh api` still prints the raw error JSON to stdout, which
would otherwise land in `ITEM_ID` as a non-empty "id". `first:100` is the
connection's maximum page; it counts the boards one issue is on, not the cards
on a board, so it has no board-size exposure.

```sh
N=<ISSUE_NUMBER>
ITEM_ID=$(gh api graphql -F n="$N" -f query='query($n:Int!){
repository(owner:"modelcontextprotocol",name:"inspector"){issue(number:$n){
projectItems(first:100){nodes{id project{id}}}}}}' \
--jq '.data.repository.issue.projectItems.nodes[]
| select(.project.id=="PVT_kwDOCt2Azc4BJVxt") | .id') || ITEM_ID=
[ -n "$ITEM_ID" ] || echo "#$N has no card on #28 (or the lookup failed)" >&2
```

⚠️ **Filter by repository, not by number alone.** These are **org** projects and
issue numbers are **repo-local**, so an unfiltered `select` can match another
repo's issue that happens to share the number — board #11 really does carry a
`modelcontextprotocol/servers` card — and then moves or deletes the wrong card,
or passes two ids at once (Copilot).
Then edit it — e.g. Status → In Review, when its PR opens:

```sh
ITEM_ID=$(gh project item-list 28 --owner modelcontextprotocol --format json --limit 500 \
--jq '.items[] | select(.content.repository=="modelcontextprotocol/inspector"
and .content.number==<ISSUE_NUMBER>) | .id')
# e.g. Status → In Review, when its PR opens
gh project item-edit --project-id PVT_kwDOCt2Azc4BJVxt --id "$ITEM_ID" \
--field-id PVTSSF_lADOCt2Azc4BJVxtzg5iI8c --single-select-option-id 159c8a02
if [ -n "$ITEM_ID" ]; then
gh project item-edit --project-id PVT_kwDOCt2Azc4BJVxt --id "$ITEM_ID" \
--field-id PVTSSF_lADOCt2Azc4BJVxtzg5iI8c --single-select-option-id 159c8a02
else
echo "no ITEM_ID — nothing edited" >&2
fi
```

### Delete a card
Expand All @@ -150,10 +222,13 @@ not planned / obsolete / superseded shipped nothing, so its card is **deleted**,
not parked in Done:

```sh
ITEM_ID=$(gh project item-list 28 --owner modelcontextprotocol --format json --limit 500 \
--jq '.items[] | select(.content.repository=="modelcontextprotocol/inspector"
and .content.number==<ISSUE_NUMBER>) | .id')
gh project item-delete 28 --owner modelcontextprotocol --id "$ITEM_ID"
# ITEM_ID from the issue-side LOOKUP block in "Move an existing card" above —
# the lookup only, not the item-edit that follows it.
if [ -n "$ITEM_ID" ]; then
gh project item-delete 28 --owner modelcontextprotocol --id "$ITEM_ID"
else
echo "no ITEM_ID — nothing deleted" >&2
fi
```

Deleting the card removes it from the board only — **the issue itself is
Expand Down Expand Up @@ -198,7 +273,8 @@ Safe alternatives, in order of preference:
**including its `id`**, appending only the new one.
`ProjectV2SingleSelectFieldOptionInput.id` is an optional `String`, so a mixed
list works. Verify afterward that no card lost its value — snapshot
`gh project item-list … --format json` before and after and diff; don't just
`gh project item-list … --format json --limit 2000` before and after, check
each is complete the way the snapshot below does, and diff; don't just
spot-check. Send those dumps to `$BOARD_TMP` too, for the reason above.

Both the `Incoming` Status option and the Urgent/High/Medium/Low Priority
Expand All @@ -220,11 +296,17 @@ PR (Copilot).

```sh
BOARD_TMP=$(mktemp -d)
gh project item-list 28 --owner modelcontextprotocol --format json --limit 600 \
gh project item-list 28 --owner modelcontextprotocol --format json --limit 2000 \
> "$BOARD_TMP/board-snapshot.json"
echo "snapshot: $BOARD_TMP/board-snapshot.json" # note the path; you need it to recover
# A truncated snapshot cannot restore the cards it dropped — refuse to proceed on one.
jq -e '(.items | length) == .totalCount' "$BOARD_TMP/board-snapshot.json" >/dev/null \
&& echo "snapshot: $BOARD_TMP/board-snapshot.json" \
|| { echo "SNAPSHOT INCOMPLETE — raise --limit and retake it before editing options" >&2
rm -f "$BOARD_TMP/board-snapshot.json"; false; }
```

Note the printed path; you need it to recover.

### Recovering from a deleted option

This has happened twice — once via the API (~197 items, reconstructed by
Expand All @@ -241,25 +323,40 @@ and pass the Priority field id `PVTSSF_lADOCt2Azc4BJVxtzg5iJE4`.
# 0. Same temp dir the snapshot went to — keep every dump out of the worktree.
BOARD_TMP=${BOARD_TMP:-$(mktemp -d)}

# 1. Which cards lost their value, and what did they hold?
gh project item-list 28 --owner modelcontextprotocol --format json --limit 600 \
# 1. Which cards lost their value, and what did they hold? lost-ids.json is
# kept ONLY when the dump is complete AND the snapshot reports what those cards
# held — step 3 refuses to run without it, so neither a truncated dump nor a
# missing snapshot can turn into a silent no-op or an unconfirmed re-apply.
rm -f "$BOARD_TMP/lost-ids.json"
gh project item-list 28 --owner modelcontextprotocol --format json --limit 2000 \
> "$BOARD_TMP/board-broken.json"
jq -r '[.items[]|select(.status==null)|.id]' "$BOARD_TMP/board-broken.json" \
> "$BOARD_TMP/lost-ids.json"
jq -r --slurpfile L "$BOARD_TMP/lost-ids.json" '($L[0]) as $lost
| [.items[] | select(.id as $i | $lost|index($i)) | .status // "(none)"]
| group_by(.) | map({s:.[0],c:length}) | .[] | "was \(.s): \(.c)"' \
"$BOARD_TMP/board-snapshot.json"
if jq -e '(.items | length) == .totalCount' "$BOARD_TMP/board-broken.json" >/dev/null; then
jq -r '[.items[]|select(.status==null)|.id]' "$BOARD_TMP/board-broken.json" \
> "$BOARD_TMP/lost-ids.json" || rm -f "$BOARD_TMP/lost-ids.json"
jq -r --slurpfile L "$BOARD_TMP/lost-ids.json" '($L[0]) as $lost
| [.items[] | select(.id as $i | $lost|index($i)) | .status // "(none)"]
| group_by(.) | map({s:.[0],c:length}) | .[] | "was \(.s): \(.c)"' \
"$BOARD_TMP/board-snapshot.json" \
|| { echo "no usable snapshot — cannot confirm what these cards held; not re-applying" >&2
rm -f "$BOARD_TMP/lost-ids.json"; }
else
echo "board-broken.json INCOMPLETE — raise --limit and re-run step 1" >&2
rm -f "$BOARD_TMP/board-broken.json"
fi

# 2. Recreate the option, echoing every surviving option's id (see above).
# NOTE: the recreated option gets a NEW id — the deleted one never comes back.

# 3. Re-apply it to the orphaned cards.
for id in $(jq -r '.[]' "$BOARD_TMP/lost-ids.json"); do
gh project item-edit --project-id PVT_kwDOCt2Azc4BJVxt --id "$id" \
--field-id PVTSSF_lADOCt2Azc4BJVxtzg5iI8c --single-select-option-id <NEW_OPTION_ID>
sleep 0.4
done
if [ -s "$BOARD_TMP/lost-ids.json" ]; then
for id in $(jq -r '.[]' "$BOARD_TMP/lost-ids.json"); do
gh project item-edit --project-id PVT_kwDOCt2Azc4BJVxt --id "$id" \
--field-id PVTSSF_lADOCt2Azc4BJVxtzg5iI8c --single-select-option-id <NEW_OPTION_ID>
sleep 0.4
done
else
echo "no lost-ids.json — step 1 did not complete; nothing re-applied" >&2
fi
```

Step 1's grouping is the safety check: confirm the orphaned set is exactly the
Expand Down
5 changes: 4 additions & 1 deletion .claude/skills/issue-create/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,10 @@ query, and an unmilestoned one drops out of release planning silently.

**Never create a duplicate.** Check the board for a matching item first.
**Never create a draft card** (a board card with no issue number) — every board
item is a real GitHub issue.
item is a real GitHub issue. The single exception is a **GitHub security
advisory**, which is private until it is published and so cannot be tracked by
an issue at all; see `/security-advisory`. Nothing you reach through *this*
flow is that case.

## 0. Check the board first

Expand Down
Loading
Loading