Last time I tried to use this, it wouldn’t pass dependency vulnerability scanning to bring it into the company. Obviously it’s not going into production, but it doesn’t seem a big ask to eliminate known CVEs.
They didn’t seem interested in resolving!