Dependabot identifies instances where we should bump some package versions. https://github.com/google/sbsim/security/dependabot We should resolve these errors. We may need to check the versions used internally, and try to match them up.