How I do it is, run npm list --all then check the completely dependency tree to find out if anywhere I am using the vulnerable package.