Security todo
2FA enforcement is org/account-level and could not be verified here, but panbanda is the sole admin with full push/admin/maintain rights and owns the crates.io publish path. A phished password on that one account is the whole ballgame. Enable 2FA (prefer passkey/WebAuthn over SMS) on the maintainer account, and require 2FA for any future collaborators or the owning org.
Context
- Severity: High
- Category: account_access_control
- Confidence: Unverified
- Threat: Compromised contributor — account takeover via credential theft is the cheapest path to repo + publish control.
Evidence
collaborators list only panbanda with admin=true; 2FA status is not readable from the API.
Security todo
2FA enforcement is org/account-level and could not be verified here, but panbanda is the sole admin with full push/admin/maintain rights and owns the crates.io publish path. A phished password on that one account is the whole ballgame. Enable 2FA (prefer passkey/WebAuthn over SMS) on the maintainer account, and require 2FA for any future collaborators or the owning org.
Context
Evidence
collaborators list only panbanda with admin=true; 2FA status is not readable from the API.