For some time now at least some developers have been receiving security warnings from GitHub. These are warnings about very old upstream packages that have known security issues, but which are nevertheless still used by nightwatch. Or at least appear to be used by nightwatch.
There are currently five warnings that come from the webapp/Dockerfiles/app/requirements.txt file: https://github.com/desihub/nightwatch/security/dependabot