Github is telling me that a dependency in my package-lock.json file is vulnerable and outdated. The problem is that if I do npm install or npm update
Edit package-lock.json manually and update vulnerable package version to the fixed one and then use
npm ci
That will install the packages according to package-lock.json by ignoring package.json first. Then use
npm audit fix
again, to be sure if it's properly done. If it does not help so, then use other given solutions.
More Information here:
https://blog.npmjs.org/post/171556855892/introducing-npm-ci-for-faster-more-reliable
or here: https://docs.npmjs.com/auditing-package-dependencies-for-security-vulnerabilities