Users of flow-coverage-report have Inefficient Regular Expression Complexity "vulnerability" CVE-2021-3803 via transitive dependency badge-up / svgo@1.3.2 / css-select / nth-check@1.0.2. Upgrading to latest svgo links a non-vulnerable version of nth-check.
One trouble is yahoo/badge-up#21 isn't merging. We could pull it into your fork in rpl/badge-up#1 and then upgrade the fork version here.