GitHub Security & compliance

Org does not require two-factor authentication

Part of the Repository protection posture check · fix arrives as a guide

What it is

The GitHub organisation does not require two-factor authentication for its members.

Why it matters

One reused or phished password is then enough to reach your source, your Actions secrets, and your published packages. Organisation accounts are a standing target precisely because of what they reach.

How to fix it

Enable the organisation-wide 2FA requirement, after giving members notice — accounts without 2FA are removed when it takes effect. Prefer passkeys or hardware keys over SMS.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.