Use `npx aud` instead of `npm audit`, whether you have a lockfile or not!
github.com/ljharb/aud
ljharb/aud