The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any…
mitre·CWE-347·Published 2019-05-16