Currently strip-ansi@^3.0.1 has a dependency on a vulnerable version of ansi-regex. The vulnerability is only fixed in ansi-regex >6.0.0, https://github.com/chalk/ansi-regex/releases/tag/v6.0.1
Additionally string-width depends on a version of strip-ansi that is vulnerable.
Vulnerability link - https://snyk.io/vuln/npm:ansi-regex