Bump updates the project's version, updates/creates the changelog, makes the bump commit, tags the bump commit and makes the release to GitHub. Opinionated but configurable.
@tcelestino don't worry about those, there's nothing to worry about, unless you're letting your users define your bump configuration or something crazy like that.
Running
npm audit
inside my project, there are warning about 4 security issues.Security alert: