Supply Chain Attacks
Firefox add-on supply chain: how Mozilla's posture differs from Chrome's
Mozilla Add-ons applies mandatory signing, a stricter review path for extensions that touch broad permissions, and a separately maintained recommended-extensions program. Here is what that buys defenders in 2026 and where the gaps still are.
May 12, 20268 min read