I have installed the libxmljs package at version 1.0.9. The code is working as expected, but I am hitting a couple of vulnerabilities during the scan that prevents the code from being deployed. These are coming from an underlying git submodule that is being used. These have been fixed, but it would seem libxmljs is still using the older level.
I've opened an issue in the libxmljs repository, but haven't received a response so far. I'm asking here in case anyone else has hit this issue and knows of a work around. I did try rebuilding the package, but was not able to get very far. Not sure my environment is right for this.