An unencrypted copy of Mozilla's previous GPG signing subkey was inadvertently committed to a private GitHub repository, prompting the organization to move to a new subkey for signing certain Firefox and Thunderbird artifacts.
log in to read full article