As of March 2023, GitHub required all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA). If you were in an eligible group, you would have received a notification email when that group was selected for enrollment, marking the beginning of a 45-day 2FA enrollment period, and you would have seen banners asking you to enroll in 2FA on GitHub.com. If you didn't receive a notification, then you were not part of a group required to enable 2FA, though we strongly recommend it.
About eligibility for mandatory 2FA
Your account is selected for mandatory 2FA if you have taken some action on GitHub that shows you are a contributor. Eligible actions include:
- Publishing an app or action for others
- Creating a release for your repository
- Contributing to specific high-importance repositories, such as the projects tracked by the Open Source Security Foundation
- Being an administrator or a contributor of a high-importance repository
- Being an organization owner for an organization containing repositories or other users
- Being an administrator or a contributor for repositories that published one or more packages
- Being an enterprise administrator
GitHub is continually assessing improvements to our account security features and 2FA requirements, so these criteria may change over time.
About mandatory 2FA for organizations and enterprises
Mandatory 2FA is required by GitHub itself to improve security for both individual developers and the broader software development ecosystem. Your administrator may also require 2FA enablement as a requirement to join their organization or enterprise, but those requirements are separate from this program. To find which users have enabled 2FA or are required to do so, see Viewing people in your enterprise or Viewing whether users in your organization have 2FA enabled.
Your account's eligibility for mandatory 2FA does not impact the eligibility of other individuals. For example, if you are an organization owner, and your account is eligible for mandatory 2FA, that does not impact the eligibility of other accounts within your organization.