npm Community Forum (Archive)

The npm community forum has been discontinued.

To discuss usage of npm, visit the GitHub Support Community.

npm audit returns unhelpful / inconsistent report

I ran npm audit, and expected to recognise the values in dependecy of from my package,json. The last entry was:
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Low │ Regular Expression Denial of Service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ timespan │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ 99cdeaf0e6a2e064df933f675d267196083f3574d537a9398422a1cc715… │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ 99cdeaf0e6a2e064df933f675d267196083f3574d537a9398422a1cc715… │
│ │ > timespan │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://npmjs.com/advisories/533
└───────────────┴──────────────────────────────────────────────────────────────┘

each time I ran it I got a different SHA, but otherwise identical last entry.

Platform Info

$ npm --versions
{ plait: '0.0.1',
  npm: '6.7.0',
  ares: '1.14.0',
  cldr: '33.1',
  http_parser: '2.8.0',
  icu: '62.1',
  modules: '64',
  napi: '3',
  nghttp2: '1.34.0',
  node: '10.13.0',
  openssl: '1.1.0i',
  tz: '2018e',
  unicode: '11.0',
  uv: '1.23.2',
  v8: '6.8.275.32-node.36',
  zlib: '1.2.11' }

$ node -p process.platform
linux