Package integrity and yarn.lock/package-lock.json

I would recommend downloading the files and checking them into your source control, say like so:

curl https://api.observablehq.com/@fil/tissots-indicatrix.tgz?v=3 | tar xvz