受贿是什么意思| 怀孕初期吃什么补充营养| 空调自动关机是什么原因| 榄仁叶是什么树的叶子| 来例假不能吃什么| 什么玉最好有灵性养人| 检查怀孕要做什么检查| 豆包是什么| 狗刨坑是什么征兆| 壁虎长什么样| 蓝颜知己什么意思| 胃胀是什么原因导致的| 可好是什么意思| 验血能查出什么| 益生菌对人体有什么好处| 熊喜欢吃什么食物| 花生吃多了有什么坏处| 结婚五十年是什么婚| 肌肉拉伤有什么症状| 姜对头发有什么作用| 4月29号0点是什么时候| 男人手大代表什么| 不偏不倚是什么意思| 淋巴细胞是什么| 低头族是什么意思| 低压高吃什么降压药好| 胃有灼热感是什么原因| 即兴表演是什么意思| 例假提前来是什么原因| 脸麻是什么原因| 胆汁反流用什么药| 腿老是抽筋是什么原因| 荒淫无度是什么意思| 肚子胀不消化吃什么药| 舌头干燥是什么原因| 为什么大便会拉出血| 肺气囊是什么病| 什么牌子的蜂蜜比较好| 宝宝发烧挂什么科| r医学是什么意思| 荷花是什么时候开的| 割伤用什么药愈合伤口| 头皮发麻什么原因| 寓教于乐什么意思| 肚脐下方硬硬的是什么| 眼有眼屎是什么原因| 胆囊炎吃什么好| 什么字寓意好| ifu是什么意思| 痤疮是什么| 内热是什么原因引起的| 脑梗的症状是什么| 鸡蛋液是什么| 人为什么会怕鬼| 芙蓉花又叫什么花| 神夫草抑菌乳膏主治什么| 10.17是什么星座| 什么样的长城| 风湿性关节炎挂什么科| 紧锣密鼓是什么意思| 黎明是什么时间| 爆粗口是什么意思| 口炎读什么| 什么的果子| 阳虚吃什么中药| 形同陌路什么意思| 小孩咳嗽挂什么科| 卵巢囊肿吃什么食物好| 结肠炎吃什么药| icu和ccu有什么区别| 蝉是什么意思| 为什么医生说直肠炎不用吃药| 肚子痛什么原因| 桃子什么季节成熟| 胃疼的人吃什么最养胃| 能力是什么意思| 灵魂摆渡是什么意思| 什么叫刑事拘留| 反复发烧是什么原因| 什么时间运动减肥效果最好| 陈皮治什么病| 童心未泯是什么意思| 左顾右盼的顾是什么意思| 什么地开放填空| 胃酸吃什么能马上缓解| 香精是什么东西| 请柬写伉俪什么意思| 尿酸低有什么危害| 舌头痒是什么原因| 阿昔洛韦片是什么药| 侯字五行属什么| 扁桃体发炎是什么引起的| 十二是什么意思| 吃什么容易上火| 舌头边缘有齿痕是什么原因| bv中间型是什么意思| 自叹不如什么意思| eb病毒是什么意思| 男生进入是什么感觉| moo是什么意思| 手指甲软薄吃什么补| 凯旋归来是什么意思| 2004是什么年| 发冷发热是什么原因| 王八吃什么| 燚是什么意思| 黄瓜有什么营养价值| adp是什么| 后背发麻是什么原因| 胃不舒服恶心想吐吃什么药| 长期喝蜂蜜有什么好处| 什么程度才需要做胃镜| 什么药治失眠最有效| 地球是什么生肖| 什么叫同工同酬| 脚趾骨折是什么感觉| 婆婆是什么意思| 麻油跟香油什么区别| cea是什么检查项目| 末梢神经炎吃什么药| 头发是什么组织| 肝硬化吃什么好| 嘴巴干苦是什么原因| 什么是埋线减肥| 生孩子送什么花| 品学兼优是什么意思| 办离婚证需要带什么证件| 什么颜色可以调成紫色| 铁剂什么时候吃最好| 人参长什么样子图片| 梦见吃水饺是什么预兆| 感冒吃什么饭菜比较好| 自白是什么意思| 桑葚什么季节成熟| 四级专家是什么级别| dunk是什么意思| 嘉靖为什么不杀严嵩| 肾不纳气用什么中成药| 舌头白苔厚是什么原因| gn是什么颜色| 平年是什么意思| 肾精亏虚是什么意思| 忠诚是什么意思| 七月半是什么日子| 尿检白细胞阳性是什么意思| 再生障碍性贫血是什么病| 睁一只眼闭一只眼是什么意思| zoe是什么意思| 加拿大属于什么洲| 回南天什么意思| 风热感冒用什么药| 头皮特别痒是什么原因| 红丹是什么| 慕斯蛋糕是什么意思| 男生为什么要割包皮| 西瓜为什么是红色的| 口巴念什么| 经常熬夜喝什么汤好| 垒是什么意思| 尿糖一个加号是什么意思| 胡萝卜炒什么好吃| 小孩办身份证需要什么材料| 踏马什么意思| 走马观花是什么意思| 什么人生病从来不看医生| rhe阴性是什么意思| 颈椎压迫手麻吃什么药| 及是什么意思| 三叉神经痛挂什么科就诊| 孤辰寡宿是什么意思| 滑石是什么| 1963年属兔的是什么命| 啧啧啧什么意思| 德比什么意思| 妯娌是什么意思| 上什么环最好最安全伤害小| 扒灰什么意思| 精子不液化吃什么药| 手心经常出汗是什么原因| 牡丹是什么意思| 脾气是什么意思| 一个山一个脊念什么| 结石是什么原因引起的| 中性粒细胞百分比偏低是什么意思| 中午12点到1点是什么时辰| 草木皆兵的意思是什么| 痛风病人吃什么菜| 得莫利是什么意思| friend什么意思中文| 1964年属什么| giuseppe是什么牌子| 公费医疗什么意思| 空调输入功率是什么意思| 红细胞分布宽度偏低是什么意思| 荨麻疹不能吃什么食物| pvt是什么意思| 什么药治便秘效果最好最快| 薤白的俗名叫什么| 为什么会有脚气| 系带断裂有什么影响吗| 什么手机像素好| 女人右眼跳预示着什么| 什么是疣| 抗hp治疗是什么意思| 皮肤有白点是什么原因| 舌苔发紫是什么原因| 阻生齿是什么意思| 1983是什么年| 什么来什么去| 肛检是检查什么| 消化不良吃什么食物好| 肌筋膜炎吃什么药| 磨牙是什么原因| na什么意思| 蚊子爱咬什么样的人| 玮五行属什么| 颈椎病有什么症状| 血糖高什么原因引起| 意尔康属于什么档次| 白色念珠菌是什么| 郁金香的花语是什么| 女人胃寒吃什么好得快| 牙齿深覆合是什么意思| 鸭子为什么会游泳| 转氨酶高有什么危害| 得了梅毒会有什么症状| 什么样的人容易得甲减| 蚊子喜欢什么味道| 语文是什么| 气道高反应是什么意思| 佐匹克隆片是什么药| 甲流乙流吃什么药| aqi是什么意思| 固液法白酒是什么意思| 达泊西汀是什么药| 喉咙干疼吃什么药| 陆地上最重的动物是什么| 单亲妈妈是什么意思| 什么叫甲状腺| 足字旁的有什么字| 甲状腺什么不能吃| 优甲乐是什么药| 休学什么意思| 清洁度lv是什么意思| 浑身疼是什么原因| 下巴老是长痘痘是什么原因| 绿鼻涕是什么原因| 剪刀是什么生肖| 命好的人都有什么特征| 上热下寒吃什么中成药| 肺炎吃什么药效果好| 血清谷丙转氨酶偏高是什么意思| 狐臭和汗臭有什么区别| 郑中基为什么叫太子基| 去海边玩需要带什么| 花甲之年是什么意思| 痔疮最怕吃什么| 淀粉是什么| 碘是什么| 立秋那天吃什么| 一对什么| tct检查是什么检查| 能量是什么意思| uniqlo是什么牌子| 百度
Skip to main content

发展智慧气象 科学抵御风险

百度 万立骏要求,要扎实做好2018年各项工作,在重大工作、重点项目上抓实见效。

Enable mandatory two-factor authentication to secure your account and maintain access to GitHub.com.

As of March 2023, GitHub required all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA). If you were in an eligible group, you would have received a notification email when that group was selected for enrollment, marking the beginning of a 45-day 2FA enrollment period, and you would have seen banners asking you to enroll in 2FA on GitHub.com. If you didn't receive a notification, then you were not part of a group required to enable 2FA, though we strongly recommend it.

About eligibility for mandatory 2FA

Your account is selected for mandatory 2FA if you have taken some action on GitHub that shows you are a contributor. Eligible actions include:

  • Publishing an app or action for others
  • Creating a release for your repository
  • Contributing to specific high-importance repositories, such as the projects tracked by the Open Source Security Foundation
  • Being an administrator or a contributor of a high-importance repository
  • Being an organization owner for an organization containing repositories or other users
  • Being an administrator or a contributor for repositories that published one or more packages
  • Being an enterprise administrator

GitHub is continually assessing improvements to our account security features and 2FA requirements, so these criteria may change over time.

Note

If your account has an education coupon active, it is exempt from mandatory 2FA.

About mandatory 2FA for organizations and enterprises

Mandatory 2FA is required by GitHub itself to improve security for both individual developers and the broader software development ecosystem. Your administrator may also require 2FA enablement as a requirement to join their organization or enterprise, but those requirements are separate from this program. To find which users have enabled 2FA or are required to do so, see Viewing people in your enterprise or Viewing whether users in your organization have 2FA enabled.

Your account's eligibility for mandatory 2FA does not impact the eligibility of other individuals. For example, if you are an organization owner, and your account is eligible for mandatory 2FA, that does not impact the eligibility of other accounts within your organization.

Note

GitHub Enterprise Managed Users and on-premise GitHub Enterprise Server users are not required to enable 2FA. Mandatory 2FA enablement only applies to users with a password on GitHub.com.

About failure to enable mandatory 2FA

If you do not enable 2FA within the 45 day setup period, and you allow the 7 day grace period to expire, you will not be able to access GitHub.com until you enable 2FA. If you attempt to access GitHub.com, you will be prompted to enable 2FA.

If you fail to enable mandatory 2FA, tokens that belong to your account will continue to function since they are used in critical automation. These tokens include personal access tokens and OAuth tokens issued to applications to act on your behalf. Enabling 2FA will not revoke or change the behavior of tokens issued for your account. However, locked accounts will not be able to authorize new apps or create new PATs until they've enabled 2FA.

About required 2FA methods

We recommend setting up a time-based one-time password (TOTP) app as your primary 2FA method, and adding a passkey or security key as a backup. If you don't have a passkey or security key, the GitHub Mobile app is a good backup option as well. SMS is reliable in most countries, but has security risks that some threat models may not work with.

Currently, we don't support passkeys or security keys as primary 2FA methods since they are easy to lose and do not support sync across a wide enough range of devices. As passkeys are more widely adopted and sync support is more prevalent, we will support them as a primary method.

Note

We recommend retaining cookies on GitHub.com. If you set your browser to wipe your cookies every day, you'll never have a verified device for account recovery purposes, as the _device_id cookie is used to securely prove you've used that device previously. For more information, see Recovering your account if you lose your 2FA credentials.

About TOTP apps and mandatory 2FA

TOTP apps are the recommended 2FA factor for GitHub. For more information on configuring TOTP apps, see Configuring two-factor authentication.

If you do not want to download an app on your mobile device, there are multiple options for standalone TOTP apps that run across platforms. For desktop applications, we recommend KeePassXC, and for browser-based plugins, we recommend 1Password.

You can also manually set up any app that generates a code compatible with RFC 6238. For more information on manually setting up a TOTP app, see Configuring two-factor authentication. For more information on RFC 6238, see TOTP: Time-Based One-Time Password Algorithm in the IETF documentation.

Note

If you are using FreeOTP for 2FA, you may see a warning about weak cryptographic parameters. GitHub uses an 80 bit secret to ensure compatibility with older versions of Google Authenticator. 80 bits is lower than the 128 bits recommended by the HOTP RFC, but at this time we have no plans to change this and recommend ignoring this message. For more information, see HOTP: An HMAC-Based One-Time Password Algorithm in the IETF documentation.

About SAML SSO and mandatory 2FA

If you have been selected for mandatory 2FA, you must enroll in 2FA on GitHub.com even if your company already requires single sign-on (SSO) with 2FA. While SSO with 2FA is a powerful way to protect organization or enterprise-owned resources, it does not protect user-owned content on GitHub.com unrelated to an organization or enterprise, nor does it protect a user's profile and settings.

GitHub only requires you to perform 2FA on the initial authentication and for sensitive actions, so even if you have to perform corporate 2FA every day to access GitHub, you will rarely have to perform 2FA a second time through GitHub. For more information on sensitive actions, see Sudo mode.

About email verification and mandatory 2FA

When you log in to GitHub.com, email verification does not count as 2FA. Your account's email address is used for password resets, which are a form of account recovery. If an attacker has access to your email inbox, they can reset the password for your account and pass the email device verification check, reducing your account's protection to a single factor. We require a second factor to prevent this scenario, so that second factor must be distinct from your email inbox. When you enable 2FA, we will no longer perform email verification on login.

About service accounts and mandatory 2FA

Unattended or shared access accounts in your organization, such as bots and service accounts, that are selected for mandatory two-factor authentication, must enroll in 2FA. Enabling 2FA will not revoke or change the behavior of tokens issued for the service account. GitHub recommends securely storing the TOTP secret of the service account in shared credential storage. For more information, see Managing bots and service accounts with two-factor authentication.

About your privacy with mandatory 2FA

If you have been selected for mandatory 2FA, that does not mean you have to provide GitHub with your phone number. You only have to provide your phone number if you use SMS for 2FA. Instead, we recommend configuring a TOTP app as your primary 2FA method. For more information, see Configuring two-factor authentication.

Note

Your region may not be listed in the available SMS options. We monitor SMS delivery success rates on a per region basis, and disallow setup for regions that have poor delivery rates. If you don't see your region on the list, you must set up a TOTP app instead. For more information on supported regions for SMS, see Countries where SMS authentication is supported.

弥漫什么意思 飘雪是什么茶 为什么总是放屁很频繁 骨癌的前兆是什么症状 抽烟打嗝是什么情况
着床成功后有什么症状或感觉 急性心力衰竭的急救措施是什么 cinderella是什么意思 幻觉是什么意思 最毒的蛇是什么蛇
甲鱼吃什么 天煞孤星是什么意思 硬度不够吃什么药 阴道恶臭是什么原因 睡莲什么时候开花
小孩满月送什么礼物好 脖子长疣是什么原因 速度是70迈心情是自由自在什么歌 来月经喝红糖水有什么好处 明前茶什么意思
肾结石长什么样子图片helloaicloud.com 舌苔厚白中间有裂纹吃什么药hcv7jop9ns7r.cn 腹泻吃什么药好hcv8jop2ns6r.cn iron什么意思hcv8jop9ns4r.cn 喝荷叶茶有什么好处和坏处hcv7jop9ns8r.cn
验光挂什么科hcv9jop6ns0r.cn 偏袒是什么意思hcv9jop6ns6r.cn 拿的起放的下是什么意思hcv7jop9ns2r.cn 心电图窦性心动过缓是什么意思hcv8jop1ns5r.cn 瑞典和瑞士有什么区别hcv8jop5ns2r.cn
芒果对身体有什么好处hcv9jop8ns3r.cn 为什么叫西瓜hcv7jop5ns0r.cn 龙凤呈祥的意思是什么hcv8jop4ns9r.cn 重庆有什么好大学hcv7jop6ns1r.cn 郡字五行属什么hcv8jop1ns5r.cn
彼岸花是什么花hcv9jop7ns2r.cn 认真是什么意思hcv8jop1ns5r.cn 梦见着大火了是什么征兆hcv8jop7ns5r.cn 肝回声密集是什么意思1949doufunao.com 唐僧最后成了什么佛hcv9jop0ns2r.cn
百度