[{"data":1,"prerenderedAt":75},["ShallowReactive",2],{"blog-npm-enhances-security-by-restricting-bypass-2fa-granular-access-tokens":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"date":10,"tags":11,"cover":17,"body":18,"_type":69,"_id":70,"_source":71,"_file":72,"_stem":73,"_extension":74},"/blog/npm-enhances-security-by-restricting-bypass-2fa-granular-access-tokens","blog",false,"","npm enhances security by restricting bypass-2FA granular access tokens","GitHub Blog reports npm's new security control requiring interactive 2FA for sensitive actions with GATs.","2026-08-01",[12,13,14,15,16],"npm","security","2FA","GitHub","granular access tokens",true,{"type":19,"children":20,"toc":63},"root",[21,30,36,42,47,53,58],{"type":22,"tag":23,"props":24,"children":26},"element","h2",{"id":25},"strengthening-npm-security-for-sensitive-operations",[27],{"type":28,"value":29},"text","Strengthening npm security for sensitive operations",{"type":22,"tag":31,"props":32,"children":33},"p",{},[34],{"type":28,"value":35},"npm has updated its security protocols to reinforce protection around sensitive account, organization, and package management activities. Previously, certain Granular Access Tokens (GATs) configured to bypass two-factor authentication (2FA) could perform these important operations without additional verification.",{"type":22,"tag":23,"props":37,"children":39},{"id":38},"new-requirements-for-granular-access-tokens",[40],{"type":28,"value":41},"New requirements for Granular Access Tokens",{"type":22,"tag":31,"props":43,"children":44},{},[45],{"type":28,"value":46},"Moving forward, these GATs must successfully complete an interactive 2FA challenge before executing any sensitive commands. This measure closes a previously exploited gap, ensuring that managing critical parts of your npm ecosystem requires explicit user authentication.",{"type":22,"tag":23,"props":48,"children":50},{"id":49},"why-this-matters",[51],{"type":28,"value":52},"Why this matters",{"type":22,"tag":31,"props":54,"children":55},{},[56],{"type":28,"value":57},"As attacks targeting software supply chains increase, enforcing strong multi-factor authentication workflows is vital. Ensuring that automated tokens also comply with interactive security challenges makes unauthorized access more difficult, preserving the integrity of development pipelines and open source projects.",{"type":22,"tag":31,"props":59,"children":60},{},[61],{"type":28,"value":62},"Stay vigilant and update your security processes accordingly to align with npm's tightened access control policies.",{"title":7,"searchDepth":64,"depth":64,"links":65},2,[66,67,68],{"id":25,"depth":64,"text":29},{"id":38,"depth":64,"text":41},{"id":49,"depth":64,"text":52},"markdown","content:blog:npm-enhances-security-by-restricting-bypass-2fa-granular-access-tokens.md","content","blog/npm-enhances-security-by-restricting-bypass-2fa-granular-access-tokens.md","blog/npm-enhances-security-by-restricting-bypass-2fa-granular-access-tokens","md",1785568725260]