Github vulnerability

It is referring to “kramdown” which I don’t use in my repo (no idea what it is) so am assuming that comes from nbdev. Do I need to upgrade nbdev for this? I am on 02.20.

If you have a moment would you mind responding to my other query please? I’m stuck!
Importing own functions