As the next step in the journey towards a more secure GitHub experience, beginning November 13th, GitHub and Visual Studio will no longer accept account passwords when authenticating with the REST API and will instead require using token-based authentication (e.g., personal access or OAuth), for all authenticated operations for GitHub.com.
As a result of the change, Git credential helpers such as the Git Credential Manager (GCM) that authenticate via account passwords wonβt be able to create new access tokens or authenticate you for GitHub.com operations with your username and password.
What does that mean for you?
Weβll be releasing a new servicing update tomorrow (Tuesday November 10th) for Visual Studio 2017 (version 15.9.0) and Visual Studio 2019 (versions 16.0, 16.4 & 16.7), where weβll include support for the new Git Credential Manager Core (GCM Core), which supports OAuth token-based authentication. Updating to these Visual Studio versions will automatically transition you to the new GCM Core experience and ensure your experience is not impacted.
As part of this change, youβll notice that GitHub.com operations that require credentials will now only allow you to authenticate via the OAuth based web browser authentication flow:

If you are using older versions of Visual Studio and cannot update to the latest Visual Studio 2019 offering, please refer to the additional workarounds on the GCM Core GitHub page.
Wrapping up
We encourage you to take advantage of some of the other security enhancements GitHub has enabled in recent years such as: two-factor authentication,Β sign-in alerts,Β verified devices,Β preventing the use of compromised passwords, andΒ WebAuthn support. For more details see learn more about keeping your account secure, orΒ contact GitHub Support.
If you have any issues with the Visual Studio experience, we ask you to send us feedback via theΒ Developer CommunityΒ portal, or via the Help > Send Feedback feature inside Visual Studio. Weβd love to know how to further improve your experience!

Formed in 2009, the Archive Team (not to be confused with the archive.org Archive-It Team) is a rogue archivist collective dedicated to saving copies of rapidly dying or deleted websites for the sake of history and digital heritage. The group is 100% composed of volunteers and interested parties, and has expanded into a large amount of related projects for saving online and digital history.

0 comments