Cherrypick dependency vulnerability upgrades

Original MR !413 (merged)

Edited by Chad Leong

Merge request reports

Loading