It seems they use some combination of gitolite and their own stuff.
The post mentions karma, there's some code here: https://github.com/php/karma/
The post mentions karma, there's some code here: https://github.com/php/karma/
I think the most common attacks on Github repos and groups have been on individual accounts. Which 2FA would mitigate.
Or Rust, right? </sarcasm> https://github.com/php/karma/search?q=exec