CVE-2021-43616 is sonar-scanner

Hey there.

Thanks for the report. We don’t consider that we’re vulnerable. Nevertheless, we will remove npm from the next release.

https://jira.sonarsource.com/browse/DOCKER-69

In the future, please follow this guide on responsible vulnerability disclosure: