Hi, There is a vulnerability in this package, which can be updated if the dependency scss-tokenizer is at least version 0.4.3. See also: https://github.com/advisories/GHSA-7mwh-4pqv-wmr8 Could you patch this?