I've been looking into 2FA on Github and I don't understand why you must have either SMS or TOTP (typically a mobile app) as the primary second factor. Why not let users go straight to a yubikey? I don't want my mobile involved in the process at any point. You also can't remove the TOTP factor once you've added a yubikey, so yubikeys are 2nd class citizens, despite being much more secure.
The primary reason is exactly the reason you cited (u2f support is not ubiquitous across browsers..especially mobile). We may consider allowing folks to use u2f exclusively in the future, but we started conservatively given the already risky proposition of account lockout with regular 2FA.
Thank you for clearing that up. Personally, I'm more likely to lose my phone or have it brick itself (happened to my previous phone) than to lose a yubikey.