We first ignored them with a "ignore due date" which was reached last Friday.
Those vulnerabilities are unlikely, issues come from a transitive dep (which also appears to be managed by the wikimedia foundation) and it is unlikely some changes are made to it any time soon. In any cases those vulnerabilities are hardly exploitable in our context.