The node-security platform reported that `static-module` is compromised (because it includes `static-eval`), should probably move off it.