@whitequark @glyph @emma @mcc As someone publishing software on github intended to be downloaded as exes and run, I would say the responsible thing to do is not have weak authentication likely to get popped.
OTOH I don't accept that it's github's business to impose this on everyone who might be developing personal hobby projects and might be at risk of losing their account due to 2FA requirements.