Mozilla has replaced the Firefox GPG signing key used for certain Firefox and Thunderbird release files after an unencrypted copy was accidentally committed to a private GitHub repository.
The company said it found no evidence that an unauthorised party accessed the exposed key. It also assessed the risk of a supply-chain attack as low because only a small group of people could access the repository.
Even so, Mozilla revoked the previous key and moved to a new signing subkey as a precaution.
Key signed Linux release files
The affected Firefox GPG signing key was used for Linux tarballs, RPM packages and checksum files. Mozilla also used it for certain Thunderbird release artefacts.
GPG keys help users verify that software packages came from the expected publisher and have not been altered in transit. If attackers gained control of a signing key, they could potentially sign malicious software that appears legitimate.
Mozilla said the exposed copy was stored in a private repository. Access was limited to a small internal group whose members already had authorised access to the key through other means.
Its review of available audit records did not identify any unauthorised access while the key was present in the repository.
Mozilla revokes the old key
Mozilla responded by revoking the previous subkey and issuing a replacement. The new subkey will remain valid until August 5, 2028.
The company also introduced measures intended to prevent a similar exposure in the future. Although it has not disclosed every internal change, key rotation limits the risk linked to the accidentally committed copy.
Most Firefox and Thunderbird users will not need to do anything. Standard browser updates should continue to work as normal.
However, people who manually verify software signatures will need to import the new public signing key and the revocation certificate for the old one.
Some RPM users may need to update manually
Linux users who install Firefox through RPM packages may need to take additional action to keep receiving updates.
Mozilla issued separate guidance for systems running Fedora, Red Hat Enterprise Linux-based distributions, Rocky Linux, AlmaLinux, openSUSE and SUSE. The exact steps depend on the operating system version and package setup.
Thunderbird users do not need RPM-specific changes because Thunderbird does not provide official RPM packages.
The incident highlights the importance of protecting signing material across the software supply chain. Even an exposure in a private repository deserves a careful response, especially when a key validates widely distributed software.
Conclusion
Mozilla replaced the Firefox GPG signing key after an unencrypted copy appeared in a private GitHub repository. The company found no sign of unauthorised access, but it revoked the old key to reduce any residual risk. Most users can continue normally, while manual verification and some RPM users should update their trusted key information.


0 responses to “Firefox GPG Signing Key Replaced After GitHub Exposure”