sfcc-ci Version
2.12.0
NodeJS Version
20.19.4
sfcc-ci Path
No response
Host OS Details
No response
Description
We got 2 Medium security scan vulnerability issues reported for jsondiffpatch@0.4.1 package. This package is transient dependency for sfcc-ci@2.12.0 and we could not find a higher version where a fix is available for this vulnerability. For jsondiffpatch we have a higher non vulnerable version (0.7.3) available, however even when we tried to override in package.json it was still referring to old vulnerable version (0.4.1). Please let us know how can we address these medium security vulnerabilities. Also, could you please let us know why we are unable to override the vulnerable package?
Relevant log output