How is this a win for you? Now you can blindly trust any github account now that they are 2fa to update their dependencies? That assumption doesn't make sense.
First the dependencies don't have to live on github or they could have been added by a non 2fa before this change
This is going to lock many out causing fewer packages to be updated meaning things are less trustworthy on github
People who use 2fa are not related to the same group who updates their dependencies