WordPress.org to require 2FA for plugin developers by October
ID: 6d6d82cd-af42-5613-ba17-04f6cf765633
STIX ID: report--6d6d82cd-af42-5613-ba17-04f6cf765633
Feed Name: Bleeping Computer
WordPress.org will require two-factor authentication (2FA) for all accounts with commit access to plugins and themes starting October 1 to reduce supply-chain risk, and has introduced high-entropy, SVN-specific passwords to separate code push credentials from main accounts. Plugin authors using automated deployments (e.g., GitHub Actions) must update scripts to use the new SVN credentials, while the platform combines account-level 2FA and deploy-time controls due to technical limits on enforcing 2FA for existing repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
