This public CVE is reported against minimatch 3.0.4 which is a dependency of the version of npm in Node.js 14.x. @nodejs/npm could you help us with an assessment/statement on the severity applicability of this CVE in the context of npm's usage of minimatch?