Updated GPG Key for Signing Firefox and Thunderbird Releases
Summary
Mozilla Security announces rotation of the GPG signing subkey for Firefox and Thunderbird artifacts after an accidental exposure of the previous key. The post documents revocation of the old key, the new key fingerprint, and import steps for affected users, with special guidance for RPM-based distributions; most users require no action. It highlights supply chain and key management practices in a large open-source project.