The fact
This vulnerability exposes the code signing system widely used by open source developers.
An attack could make unavailable the time-stamping service critical for verifying the authenticity of software packages.
Click the link to read an article on the topic: