If you are getting static-eval security warnings through brfs, glslify, or similar transforms, your code is not vulnerable. The security warning only applies if you are passing untrusted user input into these transforms.
To clear the warning, update to static-module@^3.0.1.