conventional-changelog@2.0.3 have a vulnerability. It could be fixed by updating the pkg https://github.com/conventional-changelog/releaser-tools/blob/3fc007be5ed0865a85bcb5c8842647d6efa81688/packages/conventional-gitlab-releaser/package.json#L39