In https://github.com/iopipe/examples/blob/master/node/serverless-with-iopipe-package-json/package-lock.json , GitHub suggests that the used version should be updated to at least 5.0.3 due to this CVE: https://nvd.nist.gov/vuln/detail/CVE-2018-3728 .