It triggers a security update alert, and use it through npx, so it doesn't need to be in our package.json.