While trying to install the latest (4.6.0) plotlywidget (edit: also jupyterlab-plotly), my company's automated procurement system flagged three security issues in two of your dependencies.
Could you please update these? For the moment, these vulns means that plotlywidget is a no-go for us.
Also, I just opened essentially the same issue on plotly/jupyterlab-chart-editor#47, which has identical vuln issues.