"npm, PyPI, RubyGems, Packagist, Docker Hub, Hex.pm, Clojars, Hackage, and CPAN’s PAUSE each have a username-and-password identity system of their own, so 2FA on each has been implemented separately w
"npm, PyPI, RubyGems, Packagist, Docker Hub, Hex.pm, Clojars, Hackage, and CPAN’s PAUSE each have a username-and-password identity system of their own, so 2FA on each has been implemented separately with its own enforcement policy. PyPI is the only one where enforcement is complete." https:// nesbitt.io/2026/08/18/two-fact or-authentication-across-package-registries.html