This document describes how decisions are made in mcp-debugger. It exists so that users — including corporate and government adopters — can see exactly who is accountable for what.
mcp-debugger is stewarded by Sycamore LLC, which holds the GitHub organization, the @debugmcp npm scope, the debugmcp Docker Hub organization, and the PyPI project. The project is MIT-licensed; the license grant is irrevocable and does not depend on the steward.
- Maintainers (listed in MAINTAINERS.md) — merge authority, release authority, security-response authority.
- Contributors — anyone submitting issues or pull requests under CONTRIBUTING.md.
mcp-debugger uses an agent-first development model with human accountability: AI coding agents produce most implementation work, while humans retain all trust decisions.
- All changes go through pull requests — no direct pushes to
main(enforced server-side by branch protection). - CI is the primary quality gate: required status checks (build/test on Linux and Windows, lint, container tests) must pass.
- A human maintainer makes every merge decision and every release decision. Agents cannot merge, publish, or modify branch protection.
- Releases are tagged by a maintainer and built/published by CI with pinned actions, OIDC trusted publishing, sigstore provenance, and SBOMs (see SUPPLY-CHAIN-SECURITY.md).
Day-to-day decisions are made by the lead maintainer. Significant directional changes (new language adapters, protocol-surface changes, deprecations) are proposed and discussed in GitHub issues before implementation — the issue tracker is the project's decision record.
Vulnerability handling follows SECURITY.md: private disclosure via GitHub Security Advisories or security@debugmcp.io, coordinated release of fixes, and public advisories after patches ship.
Changes to governance require a pull request approved by the lead maintainer.