Add an opt-in allowlist so a vetted external developer who already has a
plugin live in this marketplace — but cannot use the submission form
(e.g. an enterprise partner without a Claude account) — can open a
reviewable PR instead of having it auto-closed.
- .github/external-contributors.json: username -> allowed_sources map
(doubles as the allowlist and the per-author source scope).
- close-external-prs.yml: skip the auto-close for allowlisted authors
(reads the list from the trusted base checkout). Grants ONLY the right
to open a PR; CI + maintainer approval are unchanged.
- external-pr-scope-guard.yml: required check for allowlisted external
authors. Fails unless the PR touches ONLY marketplace.json and the
delta is additions-only, with every added entry's source.url under
that author's allowed_sources. Anthropic members are unrestricted.
Reads head marketplace.json as data via the API (no untrusted checkout).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>