## Description ora version 3 pulls in a vulnerable version of strip-ansi (v4). https://github.com/react-native-community/cli/blob/master/packages/cli-types/package.json#L9 This dependency is fixed in ora version 6: https://github.com/sindresorhus/ora/commit/090860b50257f75f02dd5cd76b76025ca95311f0