Mozilla has replaced the Firefox GPG signing key used for certain Firefox and Thunderbird release files after an unencrypted copy was accidentally committed to a private GitHub repository. The company said it found no evidence that an unauthorised party accessed the exposed key. It also assessed the risk of a supply-chain attack as low because…