it appears the CVE-2022-37620 won't get fixed in the `html-minify` package, not maintained anymore as it appears, see https://github.com/kangax/html-minifier/issues/1135 On alternative would be to switch to https://github.com/posthtml/htmlnano.