Mozilla Revokes Firefox GPG Key After GitHub Exposure
TL;DR. Mozilla revoked a Firefox and Thunderbird GPG signing subkey after its accidental exposure in a GitHub repository. - The exposed key could allow attackers to sign malicious software, creating a supply chain risk. - Mozilla found no evidence of unauthorized access to the private repository. - Most users do not need action; those verifying GPG signatures must import the new key.
- Mozilla revoked a GPG signing subkey for Firefox and Thunderbird artifacts.
- The key was accidentally committed to a private GitHub repository.
- No evidence of unauthorized access to the key was found.
- The incident highlights software supply chain attack risks.
- Mozilla issued new key and added future protections.
Sources
- Mozilla Issues New Firefox GPG Key Following Exposure — securityweek.com
- theregister.com — theregister.com