Skip to main content

Publish to npm Using MFA-Enabled Accounts

Description

Publish to npm using an MFA-enabled account rather than single factor legacy or granular access tokens

Dashboard Inclusion

We use the column has_npmPublicationMFA_policy from the table projects to calculate the status, this column is populated using the bulk importer. More information

Details

  • Default Category: service authentication
  • Default Priority Group: P3
  • Implementation Details: It is manual (details).
  • C-SCRM: true
  • Mitre: CWE-308
  • Sources: npm Docs