minimatch 3.1.2 has a ReDoS vulnreability which is fixed in the last 3.1.3 release, but the current dependency tree is fixed to minimatch 3.1.2. Github advisory PR: https://github.com/github/advisory-database/pull/7002