The Avidsory https://github.com/advisories/GHSA-8mgj-vmr8-frr6 is a wildcard while npm has removed the malicious dependency v4.4.2 https://github.com/debug-js/debug/issues/1005 https://github.com/chalk/chalk/issues/656 Unless I am missing something, previous versions seem unaffected. Please update to unlock development pipelines of unaffected packages.