Implemented on March 13, GitHub requires developers to use two-factor certification (2FA)
CTOnews.com March 10, the code hosting platform GitHub announced in May last year that it will require all developers who contribute code to the platform to enable two-factor authentication (2FA). GitHub announced in a blog post today that the requirement will take effect on March 13 this year.
Requiring developers to use 2FA _ GitHub is considered to be a necessary measure to protect software development and supply chain security. Some blog posts translated by CTOnews.com are as follows:
GitHub is the core of software supply chain. To ensure the security of software supply chain, we should start with protecting developers. So we are pushing ahead with the 2FA program to protect software development by improving account security.
Developer accounts are common targets for social engineering and account takeover (ATO). Protecting developers and consumers of the open source ecosystem from such attacks is the first and most critical step in securing the supply chain.
GitHub says it will gradually advance 2FA requirements, starting with developers and administrators. These users will be alerted by email and will see banners on the web version of GitHub. Developers have 45 days to set up 2FA, followed by an one-week buffer period, and account access will be restricted if developers do not set up 2FA.
Related readings:
Safety first: GitHub requires all users who contribute code to enable two-factor authentication by the end of 2023