GitHub has expanded the implementation of mandatory two-factor authentication in the NPM repository, which will now apply to developer accounts managing packages with over 1 million weekly downloads or used as dependencies by more than 500 packages. Previously, two-factor authentication was only mandatory for maintainers of the 500 most popular NPM packages (based on the number of dependent packages).
Maintainers of significant packages will now be able to perform repository-related operations only after enabling two-factor authentication, which requires a login confirmation via one-time passwords (TOTP) generated by applications such as Authy, Google Authenticator, and FreeOTP, or hardware keys and biometric scanners that support the WebAuth protocol.
Source: opennet.ru
