Skip to content

Restricting npm bypass-2FA granular access tokens

UpdateVerifiedAdded Sep 22, 2026

npm granular access tokens (GATs) configured to bypass 2FA can no longer perform sensitive account, org, and package management actions. These now require an interactive 2FA challenge, closing one of the largest credential-based attack surfaces on the registry. This only impacts npm granular access tokens.

Read GitHub's release notes

https://github.blog/changelog/2026-07-31-restricting-npm-bypass-2fa-granular-access-tokens

Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.

More GitHub Advanced Security releases

Customize code scanning default setup at scale

Update

Customize Dependabot pull request branch names

Update

Code coverage automatic enablement in Code Quality settings

Preview

CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support

Update

Secret scanning coverage updates

Update

Also shipped on Jul 31, 2026

Web terminal on serverless GPU compute (AI Runtime) is in Public Preview

Preview
DatabricksLakeflow

OpenAI connector (Beta)

Beta

DeepSeek V4 Flash now runs updated weights on AI Gateway

Preview

Weekly: the week's data and AI releases, Tuesday mornings.