Mozilla has revoked its Firefox code signing key after an unencrypted copy was discovered in a GitHub repository. Internal audit logs indicate no unauthorized access occurred during the incident. The organization is now updating its release verification processes to prevent similar exposures.
- Firefox signing key revoked immediately after unencrypted copy surfaced on GitHub
- Audit logs confirmed no unexpected visitors or data exfiltration during the event
- Release verification workflows require updates to mitigate future signing key risks