https://github.com/eslint/eslint-scope/issues/39#issuecommen...
You can easily modify the script to scan for the other vulnerable dependency as per
https://github.com/eslint/eslint/issues/10600
version: eslint-config-eslint 5.0.2