A stolen maintainer password is a stolen repository. On 13 March 2023 GitHub 29 began requiring two-factor authentication (2FA) from everyone who contributes code on GitHub.com, rolled out group by group through 2023. Organizations can require it too (not run here). Factors differ in resisting phishing:
| Second factor | Resists phishing | Notes |
|---|---|---|
| Passkey or security key (WebAuthn) | Yes | Bound to github.com; a passkey also replaces the password |
| GitHub Mobile 29 | Partly | Approve the sign-in in the app on your phone |
| Authenticator app (TOTP) | No | Six-digit codes can be relayed by a fake site |
| SMS | No | Only in some countries; exposed to SIM swapping |
Passkeys, generally available since 21 September 2023, need neither password nor separate 2FA step: the passkey is itself two factors, a device you hold and the fingerprint or PIN that unlocks it. Register two, and keep the recovery codes offline. 2FA protects sign-ins, not tokens, so keep tokens narrow (only booknest* repositories here), short-lived (this one expires on 24 December 2026) and out of Git 1,932 , which push protection checks.