Today, we moved to a new GPG signing subkey used to sign certain Firefox and Thunderbird artifacts (namely Linux tarballs, RPM packages, checksums files) after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository. Our review of available audit records found no evidence that the key was accessed by an unauthorized party while it was present in the repository. Access to the repository was limited to a small group within Mozilla, all of whom already had authorized access to the key through other means. We have revoked the previous signing key and added safeguards to prevent similar issues in the future. For most users, no action is required. There are two cases where you may need to take action: If you manually verify our GPG signatures, you will need to import the new signing key and the revocation for the old key. If you use Firefox RPM packages, some manual intervention may be required. See the instructions below for details.…