Is npm audit more harm than good? Plus this week we look at security updates for DjVuLibre, libuv, PHP and more.