The `seroval` dependency is pinned to `~1.3.0`, which caps it at `1.3.2`. There's a security vulnerability fixed in `seroval@1.4.1`. Could the constraint be updated to `~1.4.0` or `^1.4.0`?