If the signing subkey was committed, that implies developers have it as a file on their system which I find surprising if true. They should be using hardware like a Yubikey or something. Especially for something this important.
anon7000•15m ago
The signing key for Firefox stored on a single hardware yubikey available to a single person?
noman-land•31m ago
anon7000•15m ago
computerfriend•12m ago