The package depends on the unmaintained "rc" package, recently compromised on npm.
It would be great if this dependency could be eliminated. At a minimum, unmaintained dependencies ought to be pinned to an exact version number to help mitigate supply chain attacks.
Pay now to fund the work behind this issue.
Get updates on progress being made.
Maintainer is rewarded once the issue is completed.
You're funding impactful open source efforts
You want to contribute to this effort
You want to get funding like this too