The companys directive is simple: if you contribute to code, you must enable 2FA.

GitHub is probably pushing this initiative because the number of people using adequate security measures is so low.

Last November, GitHub forcedNPM package maintainers to enroll for 2FAto avoid account takeovers.

GitHub is making 2FA mandatory for devs — here’s how to enable it

On May 31, we will be enrolling all maintainers of the top-500 packages in mandatory 2FA.

40% off TNW Conference!

GitHub also supports integration with physical security keys like Yubikey.

GitHub Settings screen

Heres how you could enable 2FA on your GitHub account:

Viola, youre done!

Watch it in action in the GIF below.

it’s possible for you to read about setting up your security for your accounthere.

You can enable 2FA through SMS or a third-party authentication app.

Hopefully, well see an uptick in accounts using 2FA before the mandatory rollout begins.

Secure your shit, people.

That’s one heck of a mixed bag.

Save your recovery codes!

He likes to say “Bleh.

That’s one heck of a mixed bag.

He likes to say “Bleh.”

Also tagged with