Mozilla has revoked and replaced the GPG signing subkey for certain Firefox and Thunderbird Linux releases after an unencrypted copy was committed to a private GitHub repository. Mozilla found no evidence of unauthorized access, but users who verify signatures manually—and administrators managing Firefox RPM packages—may need to update their trust configuration. Source
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!