Npm audit fails

As long as Node-RED pins all versions and don't allow npm to update dependent packages "Compatible with version" (See semver), the user won't be able to do so, I guess.