I think we should add a vulnerability scanner in the dependency updates flow.
PRs such as #57769, should be scanned for vulnerabilities before going through - I would also not installing things if they would pull vulnerable dependencies (not sure how easy that would be).
@aduh95 @BridgeAR @ruyadorno