基础设施 5.0 · 必读 2026-08-18 · 文章

Two-Factor Authentication Across Package Registries

Nesbitt 按账户身份来自哪里把 ecosyste.ms 上包数过万的 registry 切成四档横向对比 2FA 进度:PyPI 是唯一全员强制(2024-01 起 TOTP/WebAuthn 都收,2022 年还发过 4000 把硬件 key);npm 走 cohort 强制2026-08 关掉账户治理类操作的 2FA bypass;RubyGems 对累计下载 1.8 亿次以上 gem 强制;NuGet 2022 年起依托 MSA/AAD 最早一刀切...

打开原文回到归档

Two-Factor Authentication Across Package Registries

中文摘要

Nesbitt 按「账户身份来自哪里」把 ecosyste.ms 上包数过万的 registry 切成四档横向对比 2FA 进度:PyPI 是唯一全员强制(2024-01 起 TOTP/WebAuthn 都收,2022 年还发过 4000 把硬件 key);npm 走 cohort 强制、2026-08 关掉账户治理类操作的 2FA bypass;RubyGems 对累计下载 1.8 亿次以上 gem 强制;NuGet 2022 年起依托 MSA/AAD 最早一刀切;Maven Central 至今无 2FA,靠 PGP 签名管 artifact。CI 发包被 2FA 逼出 trusted publishing(PyPI 2023-04 落地,npm/crates.io 2025 跟进),npm 2026-05 GA 的 staged publishing 还要求版本经独立 2FA challenge 批准。这是 2026 供应链安全现状最实的一张表。

English Summary

Nesbitt slices the 2FA status of every package registry with >10k packages tracked by ecosyste.ms along "where does account identity come from": PyPI is the only fully mandatory one (and shipped 4000 hardware keys to top maintainers in 2022); npm enforces by cohort, closed the account-governance 2FA bypass in Aug 2026 per GitHub's supply-chain plan; RubyGems mandates 2FA for gems over 180M cumulative downloads; NuGet leaned on MSA/AAD earliest (new accounts forced since 2022-03); Maven Central still has no 2FA and relies on PGP signatures. 2FA at the publish stage squeezes CI into trusted publishing (PyPI 2023-04, RubyGems 2023-12, npm/crates.io 2025), and npm's staged publishing (GA 2026-05) adds a separate 2FA challenge before a version becomes installable.

原文要点(证据摘录)

  • npm 2026-08: stopped accepting bypass-2FA tokens for account-governance actions, closing reusable-credential bypass routes (github.blog plan set out 2025-09).
  • PyPI: mandatory for all since 2024-01 (TOTP/WebAuthn), 4000 hardware keys shipped 2022; trusted publishing since 2023-04.
  • NuGet: 2FA verification tied to MSA/AAD, new accounts forced since 2022-03 — the earliest platform-wide cutover.
  • Maven Central: still no client-side 2FA, PGP-signed artifacts; CocoaPods trunk email-token model, stops accepting new podspecs 2026-12-02.
  • Evidence snapshot: ~/.hermes/evidence/ak-rss-digest/2026-08-18/01-nesbitt-2fa-registries.txt

来源 / Obsidian 引用

  • 本机 Obsidian 同日材料:OpenClaw定时任务/AK-RSS-Digest(89源精选)/2026-08-18(评分 8.5/10)
  • 评分依据:原文正文/官方 release body(不靠标题或源声誉)