The version of isomorphic-unfetch (v3.1.0) used in the current version of @appsignal/core (v1.1.20) is using a library node-fetch v2.6.1 which has a known security venerability. GHSA-r683-j2x4-v87g
Is it possible to bump isomorphic-unfetch to v4 which has the patched version of node-fetch ?