Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»GITHUB Access NPM with compulsory 2FA, access tokens
    Security

    GITHUB Access NPM with compulsory 2FA, access tokens

    PineapplesUpdateBy PineapplesUpdateSeptember 23, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    GITHUB Access NPM with compulsory 2FA, access tokens
    Share
    Facebook Twitter LinkedIn Pinterest Email

    GITHUB Access NPM with compulsory 2FA, access tokens

    The GITHUB is presenting a set of defense against the supply-series attacks on the stage, causing several large-scale incidents recently.

    Notable cybercatx that began with a compromise with Github Repository and then spread to NPM, in late August, “S1ngularity” attack, “Ghostection” campaign in early September, and Worm-style campaign dubbed “shay-hulud” since last week.

    The attacks led to a compromise of thousands of accounts and private repository, theft of sensitive data and significant therapeutic costs.

    Although Github quickly responded to reduce the impact of these events, the developer platforms accept that strong active measures will be more effective.

    To reduce these risks, Github announced This will gradually implement the following measures:

    • Local publication requires two-factor authentication (2FA).
    • Apply a granular token with a lifetime of 7-day.
    • Encourage expansion and adopt Reliable publication,
    • Remove classic tokens and TOTP 2FA (migrating for Fido-based 2FA).
    • Short the end of the publishing tokens.
    • Default publication access to the tokens.
    • Remove the option to bypass 2FA for local publication.

    Reliable publications, which have already been adopted in many ecosystems, are strongly encouraged as it eliminates the need to manage the API tokens in the build system.

    NPM maintenance is advised to immediately switch to reliable publication, as well as apply 2FA for publication and writing, and use webauth instead of time-based one-time password (TOTP) for 2FA.

    The code hosting and cooperation platform will gradually roll out these changes and provide the documents and migration guides required to reduce the disruption in the existing workflows.

    The declaration also emphasized that ecosystem security is a collective duty, and developers are expected to take action themselves to reduce supply risks by adopting better security options available on stage.

    Ruby Central also announced Rubygems package manager’s tight governance to improve its supply-series safety.

    The ecosystem was recently suffering from similar problems, such as a campaign with 60 malicious ruby ​​gems that were downloaded 275,000 times, and typing the Fastlane project for a telegram.

    Only Ruby Central Staff will conduct admin access until the new regime models and the underlying policies are finalized.

    The announcement promises a change for a more transparent, community-centric model. A Q&A set for today is expected to clarify the concerns related to sudden action, which were depicted as a raw acquisition to many Ruby community members.


    Picus Blue Report 2025

    The passwords broke in 46% of the atmosphere, almost doubled by 25% last year.

    Picus Blue Report 2025 Now get a wider look at more conclusions on prevention, detection and data exfIs.

    2FA access compulsory Github NPM tokens
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleTop 25 MCP weaknesses show how AI agents can be exploited
    Next Article How a rock becomes a smartphone cpu
    PineapplesUpdate
    • Website

    Related Posts

    Startups

    Your Samsung phone has a secret Wi-Fi menu that can solve most internet problems – how to access

    December 28, 2025
    Startups

    5 AirPods Pro features that made me abandon my old pair immediately — and how to access them

    December 19, 2025
    Startups

    These 7 hidden Google Pixel Watch features I can’t live without (and how to access them)

    December 18, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    I tried 0patch as a last resort for my Windows 10 PC – here’s how it compares to its promises

    January 20, 2026

    A PC Expert Explains Why Don’t Use Your Router’s USB Port When These Options Are Present

    January 20, 2026

    New ‘Remote Labor Index’ shows AI fails 97% of the time in freelancer tasks

    January 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2026 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.