Skip to main content

Publish to npm Using MFA-Enabled Accounts

Description​

Publish to npm using an MFA-enabled account rather than single factor legacy or granular access tokens

Dashboard Inclusion​

We use the column has_npmPublicationMFA_policy from the table projects to calculate the status, this column is populated using the bulk importer. More information

Details​

  • Default Category: service authentication
  • Default Priority Group: P3
  • Implementation Details: It is manual (details).
  • C-SCRM: true
  • Mitre: CWE-308
  • Sources: npm Docs