Mozilla Corporation recently revoked a private key, utilized for signing the release packages of both the Firefox browser and Thunderbird email client, after inadvertently uploading an unencrypted GPG signing private key to a GitHub repository. As per Mozilla's official statement, this GPG private subkey was accidentally stored in a private GitHub repository. Access to this repository was restricted to a select few Mozilla internal staff members who already possessed legitimate access to the key, but the potential risk prompted the immediate revocation of the key to maintain security standards.
