Have they already enforced 2FA? The tool that I built to detect "risky" NPM/PyPI packages [1] still shows expired email domain for browserify (a top NPM package)
Well, it’s probably only enforced if you submit a new version; can’t really disable a top package just because the author hasn’t logged in in a while. browerify was last updated two years ago and probably won’t see a new release ever, so the requirement doesn’t actually matter.
Apparently it's too trivial for a release but the maintainers still seem to be around. Substack.net listed in package.json seems to be working: https://substack.net/cv.html
1. https://github.com/ossillate-inc/packj