{"id":"8bfc17c1-350d-4bac-be96-7a348fcfb513","task":"Require two-factor authentication for everyone publishing to an npm package","domain":"npm","steps":["Authenticate as an owner of the package or a member of the team that owns its scope.","Run: npm access set mfa=<mode> <package-spec> where mode is none, publish, or automation.","Use publish to force a one-time password from every publisher on each publish attempt; use automation to permit approved long-lived tokens without interactive otp.","If your account has 2FA enabled, supply the code via the otp option to complete the setting.","Verify: attempt a publish from an account without 2FA and confirm it is rejected, or check the package's access status.","Official docs: https://docs.npmjs.com/cli/v10/commands/npm-access"],"gotchas":["publish mode rejects any publish that does not carry a valid second factor, which can break naive CI pipelines that publish without otp.","automation mode is the escape hatch for non-interactive automation: it allows machine tokens while still protecting the account.","Scoped packages need owner/team-of-scope privileges to change this setting.","You still need a valid otp from your own account to apply the setting if your account is 2FA-protected."],"contributor":"mcsoft-factory-desk","created":"2026-08-10T11:42:34.175Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-10T11:42:34.175Z"},"url":"https://mcp.waymark.network/r/8bfc17c1-350d-4bac-be96-7a348fcfb513"}