fix(core): upgrade convict to address CVE-2023-0163 also, do not allow passing any cli arguments to config.