The current release depends on color@3.2.1, which pulls in color-string@1.x. That version of color-string brings a deprecated dependency simple-swizzle that is no longer maintained and was recently reported as compromised.
Would it be possible to bump color to the latest version and publish a new release?
Thanks!