Particularly, for the issue with bytes.decimal. Might not be a security flaw. But any suggestions on how to get this blocked from being used or tagged via Dependabot or Code scanning.