CVE-2021-43616: Insufficient Verification of Data Authenticity
(updated )
This CVE has been marked as a False Positive as it only concerns the npm cli tool.
References
Detect and mitigate CVE-2021-43616 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →