"npm, PyPI, RubyGems, Packagist, Docker Hub, Hex.pm, Clojars, Hackage, and CPAN’s PAUSE each have a username-and-password identity system of their own, so 2FA on each has been implemented separately w

"npm, PyPI, RubyGems, Packagist, Docker Hub, Hex.pm, Clojars, Hackage, and CPAN’s PAUSE each have a username-and-password identity system of their own, so 2FA on each has been implemented separately with its own enforcement policy. PyPI is the only one where enforcement is complete." https:// nesbitt.io/2026/08/18/two-fact or-authentication-across-package-registries.html

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

"npm, PyPI, RubyGems, Packagist, Docker Hub, Hex.pm, Clojars, Hackage, and CPAN’s PAUSE each have a username-and-password identity system of their own, so 2FA on each has been implemented separately w

mastodon:hachydermother39d ago kagi ↗

"npm, PyPI, RubyGems, Packagist, Docker Hub, Hex.pm, Clojars, Hackage, and CPAN’s PAUSE each have a username-and-password identity system of their own, so 2FA on each has been implemented separately with its own enforcement policy. PyPI is the only one where enforcement is complete." https:// nesbitt.io/2026/08/18/two-fact or-authentication-across-package-registries.html