Open
Description
Describe the bug
Hi again, I'd like to suggest a PR bumping vulnerable dependency versions to avoid the known vulnerabilities in them.
Example: I'd like to bump decode-uri-component to the 0.2.1 version in order to avoid GHSA-w573-4hg7-7wgq.
There are currently 68 vulnerabilities to be fixed (according to Scorecard analysys), let me know whether a PR would be welcome and I'll start to work on them right away.
Thanks!
Expected behavior
None
Reproduction code
No response
Reproduction URL
No response
Version
main
Environment
No response
Additional context
No response
Metadata
Metadata
Assignees
Labels
No labels