CVE details: https://github.com/advisories/GHSA-896r-f27r-55mw Patched version of json-schema is `^0.4.0` or newer (note `^0.3.0` only matches `0.3.x` when major is `0`)