secp256k1 is not a direct dependency of this project; it shows up in the dependency tree via ganache. ganache, and thus secp256k1, are development-only dependencies (they are used only for tests).
Unfortunately because development of ganache has ended, we cannot upgrade it to a version that uses a higher version of secp256k1. We may have to come up with another way of upgrade secp256k1.
Acceptance Criteria
yarn why secp256k1 should display no instances of secp256k1 using version < 4.0.4.
References
See security advisory: https://github.com/MetaMask/eth-token-tracker/security/dependabot/31