At Mozilla, a signing key for certain Firefox and Thunderbird releases ended up on GitHub in plain text. The organization has since swapped the key as a precaution. Nothing changes for most users, but some Linux users need to take action themselves.
What happened
Apparently someone at Mozilla accidentally uploaded the GPG key used to sign some Firefox and Thunderbird releases in unencrypted form. Specifically, it's a subkey the organization used to sign Linux tarballs, RPM packages, and checksum files for the two programs. According to Mozilla, the upload went only into a private repository whose access was limited to a small group within the company. Those members were already authorized to access the signing key through other means anyway.
Mozilla says it searched all relevant logs and found no evidence that an unauthorized actor obtained the key. The risk of someone abusing the key to, for example, sign manipulated versions of Firefox or Thunderbird and slip malware onto users is therefore fairly low.
Who needs to act now
Even so, Mozilla revoked the GPG key as a precaution and created a new one. It also says it has taken additional protective measures to prevent similar incidents in the future, without explaining them in detail. For most users there's nothing to do. Only those who manually verify GPG signatures or use the RPM packages for Firefox may need to switch to the new key.
Mozilla provides specific instructions for the key swap in its blog post, including for Red Hat Enterprise Linux, Rocky, AlmaLinux, SUSE, and Fedora up to and including version 42. From Fedora 43 onward there's barely anything to do, since the newer versions update the key automatically and you just need to confirm it.