benefits.gov 233 packages

Last scanned on Oct 27 at 06:52 PM
moment 2.29.1VulnerableOutdated
Parse, validate, manipulate, and display dates
License
MIT
Vulnerabilities
Moment.js vulnerable to Inefficient Regular Expression Complexity
Affected versions >=2.18.0 <2.29.4
Path Traversal: 'dir/../../filename' in moment.locale
Affected versions >=0 <2.29.2
Version distribution in production
241
2.25.1
240
2.19.0
240
2.25.0
127
2.29.1
112
2.29.3
90
2.29.4
jsonwebtoken 8.5.0 - 8.5.1VulnerableOutdated
JSON Web Token implementation (symmetric and asymmetric)
validator 13.6.0VulnerableOutdated
String validation and sanitization
markdown-it 8.4.2VulnerableOutdated
Markdown-it - modern pluggable markdown parser.
sanitize-html 1.27.5VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
semver 5.7.0 - 5.7.1Outdated
The semantic version parser used by npm.
+2
npm-cli-ops
saquibkhan
fritzy
tslib 2.1.0Outdated
Runtime library for TypeScript helper functions
ms 2.1.3
Tiny millisecond conversion utility
+4
gdborton
rauchg
matt.straka
readable-stream 3.6.0Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
safe-buffer 5.1.1 - 5.1.2Outdated
Safer Node.js Buffer API
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
uuid 8.3.2Outdated
RFC4122 (v1, v4, and v5) UUIDs
isarray 0.0.0 - 0.0.1Outdated
Array#isArray for older browsers
react-is 17.0.2Outdated
Brand checking of React Elements.
inherits 1.0.1 - 2.0.3Outdated
Browser-friendly inheritance fully compatible with standard node.js inherits()
punycode 1.4.1Outdated
A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.
mime 2.6.0 - 3.0.0
A comprehensive library for mime-type mapping
broofa
broofa
buffer 4.9.2Outdated
Node.js Buffer API, for the browser
regenerator-runtime 0.13.9Outdated
Runtime for Regenerator-compiled generator and async functions.
bytes 3.1.2
Utility to parse a string bytes to bytes and vice-versa
lodash 4.17.20 - 4.17.21
Lodash modular utilities.
@babel/runtime 7.18.3Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
entities 1.1.2Outdated
Encode & decode XML and HTML entities with ease & speed
path-to-regexp 1.8.0Outdated
Express style path to RegExp utility
core-util-is 1.0.3
The `util.is*` functions introduced in Node v0.12.
rxjs 5.5.12Outdated
Reactive Extensions for modern JavaScript
ieee754 1.2.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
util-deprecate 1.0.2
The Node.js `util.deprecate()` function with browser support
bn.js 5.2.1
Big number implementation in pure javascript
safer-buffer 2.1.2
Modern Buffer API polyfill without footguns
chalker
chalker
domutils 1.7.0Outdated
Utilities for working with htmlparser2's dom
object-assign 4.1.1
ES2015 `Object.assign()` ponyfill
base64-js 1.5.1
Base64 encoding/decoding in pure JS
core-js 2.6.12Outdated
Standard library
dom-serializer 0.2.2Outdated
render domhandler DOM nodes to a string
domhandler 2.4.2Outdated
Handler for htmlparser2 that turns pages into a dom
domelementtype 2.3.0
all the types of nodes in htmlparser2's dom
process-nextick-args 2.0.1
process.nextTick but always with args
cwmma
cwmma
util 0.11.1Outdated
Node.js's util module for all engines
events 3.3.0
Node's event emitter for all engines.
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
htmlparser2 3.10.1Outdated
Fast & forgiving HTML/XML parser
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
randombytes 2.1.0
random bytes from browserify stand alone
scheduler 0.19.1Outdated
Cooperative scheduler for the browser environment.
react 16.14.0Outdated
React is a JavaScript library for building user interfaces.
process 0.11.10
process information for node.js and browsers
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
react-dom 16.14.0Outdated
React package for working with the DOM.
jws 3.2.1 - 4.0.0
Implementation of JSON Web Signatures
jwa 1.4.1Outdated
JWA implementation (supports all JWS algorithms)
querystringify 2.2.0
Querystringify - Small, simple but powerful query string parser.
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
asap 2.0.5 - 2.0.6
High-priority task queue for Node.js and browsers
@emotion/memoize 0.6.6 - 0.7.4Outdated
emotion's memoize utility
+1
emmatown
tkh44
emotion-release-bot
hoist-non-react-statics 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
setimmediate 1.0.5
A shim for the setImmediate efficient script yielding API
domenic
domenic
lodash.isplainobject 4.0.6
The lodash method `_.isPlainObject` exported as a module.
invariant 2.2.3 - 2.2.4
invariant
@emotion/unitless 0.7.2 - 0.7.5Outdated
An object of css properties that don't accept values with units
+1
emmatown
tkh44
emotion-release-bot
promise 8.2.0Outdated
Bare bones Promises/A+ implementation
forbeslindesay
judgmentparking
then-promise-bot
react-transition-group 4.4.0 - 4.4.2Outdated
A react component toolset for managing animations
ecdsa-sig-formatter 1.0.10 - 1.0.11
Translate ECDSA signatures between ASN.1/DER and JOSE-style concatenation
d2l-travis-deploy
d2l-travis-deploy
buffer-equal-constant-time 1.0.0 - 1.0.1
Constant-time comparison of Buffers
dom-helpers 3.4.0Outdated
tiny modular DOM lib for ie9+
clsx 1.1.1 - 1.2.1Outdated
A tiny (234B) utility for constructing className strings conditionally.
@emotion/hash 0.8.0Outdated
A MurmurHash2 implementation
+1
emmatown
tkh44
emotion-release-bot
sha.js 2.4.10 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
whatwg-fetch 3.6.2Outdated
A window.fetch polyfill.
jakechampion
mattandrews
mislav
@emotion/utils 0.11.0 - 0.11.3Outdated
internal utils for emotion
+1
emmatown
tkh44
emotion-release-bot
stream-browserify 1.0.0 - 2.0.2Outdated
the stream module from node core for browsers
@emotion/serialize 0.11.14 - 0.11.16Outdated
serialization utils for emotion
+1
emmatown
tkh44
emotion-release-bot
lodash.once 4.1.1
The lodash method `_.once` exported as a module.
@emotion/cache 10.0.17 - 10.0.29Outdated
emotion's cache
+1
emmatown
tkh44
emotion-release-bot
asn1.js 5.3.0 - 5.4.1
ASN.1 encoder and decoder
hash.js 1.1.7
Various hash functions that could be run by both browser and node
stylis 4.0.13Outdated
A Light–weight CSS Preprocessor
andarist
thysultan
@emotion/sheet 0.9.1 - 0.9.4Outdated
emotion's stylesheet
+1
emmatown
tkh44
emotion-release-bot
memoize-one 4.1.0Outdated
A memoization library which only remembers the latest invocation
brorand 1.1.0
Random number generator for browsers and node.js
elliptic 6.5.4
EC cryptography
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
minimalistic-crypto-utils 1.0.1
Minimalistic tools for JS crypto modules
lodash.isstring 4.0.1
The lodash method `_.isString` exported as a module.
es5-ext 0.10.24 - 0.10.49Outdated
ECMAScript extensions and shims
hash-base 3.1.0
abstract base class for hash-streams
ripemd160 2.0.2
Compute ripemd160 of bytes or strings.
des.js 1.0.1Outdated
DES implementation
react-router 5.2.1Outdated
Declarative routing for React
pbkdf2 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
cipher-base 1.0.4
abstract base class for crypto-streams
buffer-xor 1.0.0 - 1.0.3Outdated
A simple module for bitwise-xor on buffers
create-hash 1.2.0
create hashes for browserify
md5.js 1.3.5
node style md5 on pure JavaScript
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
browserify-aes 1.2.0
aes, for browserify
create-hmac 1.1.6 - 1.1.7
node style hmacs in the browser
is-promise 2.2.0 - 4.0.0
Test whether an object looks like a promises-a+ promise
forbeslindesay
then-bot
react-router-dom 5.3.0 - 5.3.3Outdated
Declarative routing for React web applications
warning 4.0.3
A mirror of Facebook's Warning
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
parse-asn1 5.1.6
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
browserify-rsa 4.1.0
RSA for browserify
+2
dcousens
ljharb
cwmma
timers-browserify 2.0.10 - 2.0.12
timers module for browserify
browserify-sign 4.2.0 - 4.2.1
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
create-ecdh 4.0.2 - 4.0.4
createECDH but browserifiable
crypto-browserify 3.12.0
implementation of crypto for the browser
+2
dcousens
ljharb
cwmma
diffie-hellman 5.0.2 - 5.0.3
pure js diffie-hellman
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
browserify-des 1.0.2
browserify-des ===
dcousens
ljharb
cwmma
browserify-cipher 1.0.1
ciphers for the browser
cwmma
cwmma
miller-rabin 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.3 - 1.0.4
random fill from browserify stand alone
tiny-invariant 1.2.0Outdated
A tiny invariant function
redux 4.2.0Outdated
Predictable state container for JavaScript apps
history 4.10.1Outdated
Manage session history with JavaScript
lodash-es 4.17.20 - 4.17.21
Lodash exported as ES modules.
lodash.isboolean 3.0.3
The lodash method `_.isBoolean` exported as a module.
mdurl 1.0.1
URL utilities for markdown-it
vitaly
vitaly
tiny-warning 1.0.2 - 1.0.3
A tiny warning function
alexreardon
alexreardon
shallowequal 1.1.0
Like lodash isEqualWith but for shallow equal.
lodash.includes 4.3.0
The lodash method `_.includes` exported as a module.
lodash.isinteger 4.0.4
The lodash method `_.isInteger` exported as a module.
lodash.isnumber 3.0.3
The lodash method `_.isNumber` exported as a module.
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
fb
sophiebits
@emotion/react 11.0.0 - 11.10.5Outdated
> Simple styling in React.
+1
emmatown
tkh44
emotion-release-bot
p-defer 1.0.0 - 4.0.0
Create a deferred promise
react-redux 5.1.2Outdated
Official React bindings for Redux
linkify-it 2.2.0Outdated
Links recognition library with FULL unicode support
fbjs 0.8.16 - 0.8.18Outdated
A collection of utility libraries used by other Facebook JS projects
+5
zpao
eliwhite
yungsters
@emotion/stylis 0.8.4 - 0.8.5
A custom build of Stylis
+1
emmatown
tkh44
emotion-release-bot
react-select 4.3.0 - 4.3.1Outdated
A Select control built with and for ReactJS
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
uc.micro 1.0.6
Micro subset of unicode data files for markdown-it projects.
vitaly
vitaly
resolve-pathname 3.0.0
Resolve URL pathnames using JavaScript
mjackson
mjackson
resize-observer-polyfill 1.5.1
A polyfill for the Resize Observer API
value-equal 1.0.1
Are these two JavaScript values equal?
mjackson
mjackson
es6-error 4.0.1 - 4.1.1
Easily-extendable error for use with ES6 classes
hyphenate-style-name 1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
@emotion/css 10.0.0 - 10.0.27Outdated
The Next Generation of CSS-in-JS.
uncontrollable 7.2.1Outdated
Wrap a controlled react component, to allow specific prop/handler pairs to be uncontrolled
react-app-polyfill 2.0.0 - 3.0.0
Polyfills for various browsers including commonly used language features
+1
fb
timer
iansu
@emotion/core 10.3.0 - 10.3.1Outdated
+1
emmatown
tkh44
emotion-release-bot
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
react-input-autosize 3.0.0
Auto-resizing Input Component for React
rc-util 5.19.6 - 5.21.5Outdated
Common Utils For React Component
mini-create-react-context 0.3.3 - 0.4.1
Smaller Polyfill for the proposed React context API
react-overlays 0.9.3Outdated
Utilities for creating robust overlay components
@mui/material 5.0.0 - 5.10.11Outdated
React components that implement Google's Material Design.
@apollo/client 3.0.0 - 3.7.1Outdated
A fully-featured caching GraphQL client.
jss 10.0.0 - 10.9.2Outdated
A lib for generating Style Sheets with JavaScript.
is-in-browser 1.1.3Outdated
Simple check to see if current app is running in browser
tuxsudo
tuxsudo
prop-types-extra 1.1.0 - 1.1.1
React PropType Utilities
monastic.panic
monastic.panic
react-bootstrap 0.33.1Outdated
Bootstrap 5 components built with React
css-vendor 2.0.8
CSS vendor prefix detection and property feature testing.
jss-plugin-nested 10.9.0Outdated
JSS plugin that enables support for nested selectors
jss-plugin-global 10.9.0Outdated
Global styles for JSS
jss-plugin-camel-case 10.8.0 - 10.9.0Outdated
JSS plugin that allows to write camel cased rule properties
jss-plugin-default-unit 10.8.0 - 10.9.0Outdated
JSS plugin that adds default custom unit to numeric values where needed
inline-style-prefixer 3.0.8Outdated
Run-time Autoprefixer for JavaScript style objects
jss-plugin-rule-value-function 10.8.0 - 10.9.0Outdated
JSS plugin for function value and rule syntax
jss-plugin-vendor-prefixer 10.8.0 - 10.9.0Outdated
JSS plugin that handles vendor prefixes in the browser
jss-plugin-props-sort 10.0.0 - 10.9.0Outdated
JSS plugin that ensures style properties extend each other instead of override
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
css-in-js-utils 2.0.0 - 3.0.2Outdated
Useful utility functions for CSS in JS solutions
string-convert 0.1.0 - 0.2.1
String convertions
akiran
akiran
math-random 1.0.2 - 1.0.4Outdated
math-random is an isomorphic, drop-in replacement for `Math.random` that uses cryptographically secure random number generation, where available
michaelrhodes
michaelrhodes
json2mq 0.2.0
Generate media query string from JSON or javascript object
akiran
akiran
react-helmet 6.1.0
A document head manager for React
react-side-effect 2.1.0Outdated
Create components whose prop changes map to a global side effect
react-icons 4.2.0Outdated
SVG React icons of popular icon packs using ES6 imports
+2
nwwells
tusbar
gorangajic
@material-ui/utils 4.11.3
Material-UI Utils - Utility functions for Material-UI.
rc-trigger 4.3.0 - 4.3.4Outdated
base abstract trigger component for react
@material-ui/core 4.12.3Outdated
React components that implement Google's Material Design.
@material-ui/system 4.11.3 - 4.12.2
Material-UI System - Design system for Material-UI.
rc-motion 2.6.0Outdated
React lifecycle controlled motion library
@material-ui/styles 4.11.1 - 4.11.5
Material-UI Styles - The styling solution of Material-UI.
load-script 1.0.0 - 2.0.0
Dynamic script loading for browser
keycode 2.2.0Outdated
Convert between keyboard keycodes and keynames and vice versa.
enquire.js 2.1.6
Awesome Media Queries in JavaScript
rc-collapse 3.1.2 - 3.1.4Outdated
rc-collapse ui component for react
redux-saga 0.16.1 - 0.16.2Outdated
Saga middleware for Redux to handle Side Effects
react-slick 0.28.1Outdated
React port of slick carousel
nprogress 0.2.0
Simple slim progress bars
rstacruz
rstacruz
mobx-react-lite 2.2.0 - 3.0.1Outdated
Lightweight React bindings for MobX based on React 16.8+ and Hooks
@babel/runtime-corejs2 7.18.2 - 7.19.2Outdated
babel's modular runtime helpers with core-js@2 polyfilling
+1
hzoo
existentialism
nicolo-ribaudo
react-player 2.9.0Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
@chakra-ui/theme 2.1.0 - 2.1.3Outdated
The default theme for chakra components
react-loading-skeleton 2.2.0Outdated
Make beautiful, animated loading skeletons that automatically adapt to your app.
connected-react-router 6.9.0 - 6.9.2Outdated
A Redux binding for React Router v4 and v5
supasate
supasate
react-share 4.3.0 - 4.4.0Outdated
Social media share buttons and share counts for React.
lodash.isequalwith 4.4.0
The lodash method `_.isEqualWith` exported as a module.
bootstrap-vue 2.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
redux-form 8.3.6 - 8.3.8Outdated
A higher order component decorator for forms using Redux and React
redux-observable 2.0.0
RxJS based middleware for Redux. Compose and cancel async actions and more.
use-query-params 2.0.0 - 2.1.2Outdated
React Hook for managing state in URL query parameters with easy serialization.
react-html-parser 2.0.2
Parse HTML into React components
loadjs 4.2.0Outdated
Tiny async loader for modern browsers
lazysizes 5.3.1 - 5.3.2
High performance (jankfree) lazy loader for images (including responsive images), iframes and scripts (widgets).
react-google-recaptcha-v3 1.9.1 - 1.9.8Outdated
React component for google-recaptcha v3
duongtran
duongtran
@analytics/storage-utils 0.2.5 - 0.2.14Outdated
Storage utility with fallbacks
react-truncate 2.4.0
React component for truncating multi-line spans and adding an ellipsis
deepcopy 2.0.0 - 2.1.0
deep copy data
sasaplus1
sasaplus1
react-collapsible 2.8.4Outdated
React component to wrap content in Collapsible element with trigger to open and close.
glamor 2.20.40
inline css for component systems
redux-promise-middleware 5.1.1Outdated
Enables simple, yet robust handling of async action creators in Redux
jump.js 1.0.1Outdated
A modern smooth scrolling library.
callmecavs
callmecavs
adaptivecards 1.1.3Outdated
Adaptive Cards Javascript library for HTML Clients
simple-update-in 1.4.0Outdated
A lightweight `updateIn` for immutable objects.
react-scroll-to-bottom 1.2.0 - 4.2.0
React container that will auto scroll to bottom
markdown-it-for-inline 0.1.1
Inline tokens iterator for markdown-it markdown parser.
react-scrollable-anchor 0.6.1
Provide smooth scrolling anchors in React.
botframework-directlinejs 0.11.6Outdated
Client library for the Microsoft Bot Framework Direct Line 3.0 protocol
+5
botframework
sgellock
cwhitten
botframework-webchat 4.4.1 - 4.4.2Outdated
A highly-customizable web-based chat client for Azure Bot Services.
+5
botframework
sgellock
cwhitten
web-speech-cognitive-services 4.0.0Outdated
Polyfill Web Speech API with Cognitive Services Speech-to-Text service
event-as-promise 1.0.0 - 1.0.2Outdated
Handle continuous stream of events with Promise and generator function.
botframework-webchat-core 4.4.1Outdated
Core of botframework-webchat
+2
botframework
sgellock
cwhitten
botframework-webchat-component 4.4.1 - 4.4.2Outdated
React component of botframework-webchat
+2
botframework
sgellock
cwhitten
@dhmk/utils 1.0.0Outdated
A collection of frequently used functions and primitives
react-film 1.0.0 - 2.1.0Outdated
React component for showing carousel just like a film strip
react-say 1.2.0Outdated
[![npm version](https://badge.fury.io/js/react-say.svg)](https://badge.fury.io/js/react-say) [![Build Status](https://travis-ci.org/compulim/react-say.svg?branch=master)](https://travis-ci.org/compulim/react-say)
react-dictate-button 1.2.0 - 1.2.2Outdated
A button to start dictation using Web Speech API, with an easy to understand event lifecycle.
microsoft-speech-browser-sdk 0.0.12
Microsoft Speech SDK for browsers
@rooks/use-fork-ref 3.4.0 - 4.11.2
A hook that can combine two refs(mutable or callbackRefs) into a single callbackRef
react-structured-data x.x.x
remove-stopwords x.x.x
react-sweet-progress x.x.x
react-twitter-widgets x.x.x
@emotion/use-insertion-effect-with-fallbacks x.x.x
chop-lines x.x.x
react-show-more x.x.x
@material-ui/lab x.x.x