A red flag for me since it looks like this package was inactive for a bit but looks like the diff is looking okay so I’m assuming it’s just an oversight!
https://socket.dev/npm/package/moo/diff/0.5.3
Can you tag the release? Even better to get provenance setup for this so that GitHub matches what gets published to npm
Appreciate you!