since older versions of npm dont support `npm audit signatures` and instead simply audit for vulnerabilities