Mozilla GPG Key Exposed in Private GitHub Repo — Supply Chain Near-Miss
Mozilla's GPG signing subkey for Firefox and Thunderbird was inadvertently committed to a private GitHub repository, creating a direct supply chain risk: if an attacker had discovered and exfiltrated the key, they could have signed malicious artifacts that appeared legitimate to end users. Although Mozilla found no evidence of unauthorized access, the incident highlights how secrets management failures can silently undermine software integrity guarantees. Cryptographic signing keys are high-value targets because they form the root of trust for software distribution pipelines. The rapid revocation and replacement of the key, combined with added protections, demonstrates appropriate incident response — but the exposure should never have occurred in the first place.
Tactical Insight
Immediate actions
- Audit all repositories (public and private) for committed secrets, credentials, and cryptographic key material using automated secret-scanning tools.
- Rotate and revoke any exposed signing keys immediately and notify downstream consumers of the new trusted key.
Long-term improvements
- Store cryptographic signing keys exclusively in dedicated secrets management systems (e.g., HashiCorp Vault, AWS KMS, HSMs) and never in source control.
- Enforce pre-commit hooks and CI/CD pipeline checks that block commits containing key material, tokens, or other secrets before they reach any repository.
- Apply strict least-privilege access controls to repositories that touch build and release pipelines, ensuring only authorized personnel can read or write signing-related assets.
Detection & monitoring measures
- Enable GitHub Advanced Security secret scanning alerts (or equivalent) on all private repositories to receive real-time notifications of exposed credentials.
- Implement continuous monitoring and alerting on cryptographic key usage logs to detect anomalous signing activity that could indicate key compromise.