<!-- ✨ Thanks for reporting a bug! ➡️ Please don't ignore this template --> <!-- 1️⃣ Explain here what's wrong --> npm audit gives warning about the indirect `semver` dependency: `semver` <-- `normalize-package-data` <-- `read-pkg` <-- `read-pkg-up` Updating to latest version of `read-pkg-up` should mitigate this. <!-- 2️⃣ Specify which rule is buggy here and in the title --> <!-- 3️⃣ Add some examples where the issue appears -->