Restricting npm bypass-2FA granular access tokens
UpdateVerifiedAdded Sep 22, 2026
npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of the largest credential-based attack surfaces on the registry. This only impacts npm granular access tokens.
Topics: Developer tools
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Jul 29 | CodeQL 2.26.1 improves analysis accuracy and framework coverage Update | Update |
| Jul 28 | npm publish-time malware scanning and dual-use metadata Update | Update |
| Jul 28 | Dependabot alerts on malicious packages across more ecosystems Update | Update |
| Aug 4 | Customize code scanning default setup at scale Update | Update |
| Aug 4 | Customize Dependabot pull request branch names Update | Update |
| Aug 4 | Code coverage automatic enablement in Code Quality settings Preview | Preview |
| Aug 4 | CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support Update | Update |
| Aug 7 | Secret scanning coverage updates Update | Update |