serverless-appsync-plugin depends on ajv-merge-patch@^5.0.1, which depends on fast-json-patch@^2.0.6, which leads to an CVE-2021-4279 alert for projects that depend on serverless-appsync-plugin.
The ajv-merge-patch#55 would solve the problem, but the maintainer hasn't merge in a year.
Can serverless-appsync-plugin switch away from ajv-merge-patch or move to a fork with the updated dependency?