-
-
Notifications
You must be signed in to change notification settings - Fork 112
Closed
Labels
Description
Hi again,
a usual recommendation in post-mortem analyses for high-profile incidents in npm, RubyGems, etc is that 2FA should be required.
(I don't have the links for that at hand but that hopefully is an uncontroversial opinion)
While probably requiring MFA for everyone would be a little excessive today, being able to require MFA within a group does sound reasonable.
A simple proposal would be: if a group has MFA required, any members cannot deploy to that group until they activate MFA.
This way we can increase the security in both companies using Clojars, and OSS teams (e.g. cider) which have a great degree of reach.
Cheers - V
Reactions are currently unavailable