This is an ad hominem.
You don’t know anything about security measures they do or do not take — just that they don’t appreciate a vendor mandating their security policy from a position of presumed authority.
That kind of bad faith comment isn’t constructive.
The account is with the vendor in question. The vendor is literally the only entity in a position of authority.
I'll go ahead and join OP and "self-select" my way out of the all-encompassing developer community that GitHub represents, leaving you pro coders to it. Enjoy the walls around your garden.
First the dependencies don't have to live on github or they could have been added by a non 2fa before this change
This is going to lock many out causing fewer packages to be updated meaning things are less trustworthy on github
People who use 2fa are not related to the same group who updates their dependencies
This does raise the question though - should they be related? If so, why? If not, why not?
From TFA, it seems github believes that a positive correlation there is worth pursuing and they offer reasons, though I have no idea how their corporate-blog-speak relates to their actual motives here.
git secures itself. You can't "sneak" malicious code into a library if you can log into a dev's gh account. All you can do is add commits. It would be an obvious commit and the dev wouldn't push it to their package host.