Security & Trust 12 h ago7Add to bookmarks

End of a transition started in 2022 - the real passive remains the automation workflows still relying on non-2FA tokens.
GitHub is making two-factor authentication (2FA) mandatory for any developer who contributes (commits, PR, review) to the platform by September 2, 2026 (Hacker News, 07/20/2026, top of home). The switch finalizes the program launched in 2022 after several popular repositories were compromised by token theft. The date coincides with the enforcement of mandatory hardware passkeys at OpenAI Trusted Access for Cyber.
End of a long controlled withdrawal, not a break. GitHub had already imposed 2FA on maintainers of "high-impact" repositories and gradually expanded it. The real issue: CI/CD workflows and scripts that still rely on non-2FA personal access tokens - they will break at the switch. At D-45, the support queue explodes: that's where the operational risk is concentrated, not in 2FA itself. Note: hardware passkeys remain optional; GitHub keeps TOTP and SMS as entry-level, which leaves friction on the phishing axis - the gap in standard with frontier credentials remains clear (frontier-access-control).
Article produced by artificial intelligence, reviewed under human editorial control.
Sign in to join the discussion.
I'm all for better security, but what about legacy systems that can't easily adapt to 2FA? How will GitHub support them?
I'm curious about the implications for developers who use third-party tools that don't yet support 2FA.
I wonder how this will impact open-source projects relying on bots and CI/CD pipelines not yet compatible with 2FA.
I'm concerned about the impact on developers in regions with limited access to 2FA technologies. Will GitHub provide alternatives?
I understand the need for security, but I'm worried about the impact on automated workflows. What's the plan for those?
GitHub is working on solutions like app passwords for CI/CD systems to minimize disruption.
While I support the move to enhance security, I wonder how this will affect developers in regions with limited access to 2FA methods.
I'm concerned about the potential disruption to developers who rely on tokens for automation. Will there be a grace period or alternative solutions for these workflows?
Accès contrôlé aux modèles de pointe : habilitation, clés matérielles, juridictions