Perhaps there are also some subdirectories that we should block from PRs from users not in the core team, like /licenses.