
Mozilla Revokes Firefox and Thunderbird GPG Signing Key After Accidental GitHub Commit
Mozilla has rotated and revoked a GPG signing subkey used for selected Firefox and Thunderbird release artifacts after an unencrypted copy of the previous key was inadvertently committed to a private GitHub repository. In an August 10 advisory, Ben Hearsum said Mozilla’s review of available audit records found no evidence that an unauthorized party accessed […]
The post Mozilla Revokes Firefox and Thunderbird GPG Signing Key After Accidental GitHub Commit appeared first on Cyber Security News.