With granular tokens and OIDC migration in #998, we could now consider enforcing the rule to require 2fa on publishing, and even disallow tokens (including granular tokens and classic tokens) on packages hosted on https://www.npmjs.com/~nodejs-foundation.
The current available options are (this is a per-package setting):
