Open
Description
A proprietary dependency was introduced in #134 and we did not catch it. I'm pretty sure something like https://snyk.io/ or similar would have caught it. We should search/pick a tool/service that provides this and plug it into PR checks.