We add to add an override to this transitive dependency, but it would be good if it's sorted upstream. This is the CVE: https://github.com/advisories/GHSA-3ppc-4f35-3m26