Hi,
I'm working on a project, and npm audit and dependabot flags this package as being depending on vulnerable packages, namely got (through update notifier, pug, and pug-code-gen. All of these packages seem to have versions that don't have these vulnerabilities.