benefits.gov 233 packages

Last scanned on Oct 27 at 06:52 PM
moment 2.29.1VulnerableOutdated
Parse, validate, manipulate, and display dates
License
MIT
Vulnerabilities
Moment.js vulnerable to Inefficient Regular Expression Complexity
Affected versions >=2.18.0 <2.29.4
Path Traversal: 'dir/../../filename' in moment.locale
Affected versions >=0 <2.29.2
Version distribution in production
241
2.25.1
240
2.19.0
240
2.25.0
127
2.29.1
112
2.29.3
90
2.29.4
jsonwebtoken 8.5.0 - 8.5.1VulnerableOutdated
JSON Web Token implementation (symmetric and asymmetric)
browserify-sign 4.2.0 - 4.2.1VulnerableOutdated
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
validator 13.6.0VulnerableOutdated
String validation and sanitization
markdown-it 8.4.2VulnerableOutdated
Markdown-it - modern pluggable markdown parser.
sanitize-html 1.27.5VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
semver 5.7.0 - 5.7.1Outdated
The semantic version parser used by npm.
+2
npm-cli-ops
saquibkhan
fritzy
tslib 2.1.0Outdated
Runtime library for TypeScript helper functions
ms 2.1.3
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
readable-stream 3.6.0Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
safe-buffer 5.1.1 - 5.1.2Outdated
Safer Node.js Buffer API
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
uuid 8.3.2Outdated
RFC4122 (v1, v4, and v5) UUIDs
isarray 0.0.0 - 0.0.1Outdated
Array#isArray for older browsers
react-is 17.0.2Outdated
Brand checking of React Elements.
punycode 1.4.1Outdated
A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.
inherits 1.0.1 - 2.0.3Outdated
Browser-friendly inheritance fully compatible with standard node.js inherits()
mime 2.6.0 - 3.0.0Outdated
A comprehensive library for mime-type mapping
buffer 4.9.2Outdated
Node.js Buffer API, for the browser
regenerator-runtime 0.13.9Outdated
Runtime for Regenerator-compiled generator and async functions.
bytes 3.1.2
Utility to parse a string bytes to bytes and vice-versa
entities 1.1.2Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.18.3Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
lodash 4.17.20 - 4.17.21
Lodash modular utilities.
path-to-regexp 1.8.0Outdated
Express style path to RegExp utility
core-util-is 1.0.3
The `util.is*` functions introduced in Node v0.12.
rxjs 5.5.12Outdated
Reactive Extensions for modern JavaScript
ieee754 1.2.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
util-deprecate 1.0.2
The Node.js `util.deprecate()` function with browser support
safer-buffer 2.1.2
Modern Buffer API polyfill without footguns
chalker
chalker
object-assign 4.1.1
ES2015 `Object.assign()` ponyfill
domutils 1.7.0Outdated
Utilities for working with htmlparser2's dom
base64-js 1.5.1
Base64 encoding/decoding in pure JS
dom-serializer 0.2.2Outdated
render domhandler DOM nodes to a string
domhandler 2.4.2Outdated
Handler for htmlparser2 that turns pages into a dom
bn.js 5.2.1
Big number implementation in pure javascript
events 3.3.0
Node's event emitter for all engines.
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
process-nextick-args 2.0.1
process.nextTick but always with args
cwmma
cwmma
domelementtype 2.3.0
all the types of nodes in htmlparser2's dom
core-js 2.6.12Outdated
Standard library
util 0.11.1Outdated
Node.js's util module for all engines
htmlparser2 3.10.1Outdated
Fast & forgiving HTML/XML parser
scheduler 0.19.1Outdated
Cooperative scheduler for the browser environment.
randombytes 2.1.0
random bytes from browserify stand alone
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 16.14.0Outdated
React is a JavaScript library for building user interfaces.
process 0.11.10
process information for node.js and browsers
jws 3.2.1 - 4.0.0
Implementation of JSON Web Signatures
jwa 1.4.1Outdated
JWA implementation (supports all JWS algorithms)
react-dom 16.14.0Outdated
React package for working with the DOM.
querystringify 2.2.0
Querystringify - Small, simple but powerful query string parser.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
lodash.isplainobject 4.0.6
The lodash method `_.isPlainObject` exported as a module.
asap 2.0.5 - 2.0.6
High-priority task queue for Node.js and browsers
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
clsx 1.1.1 - 1.2.1Outdated
A tiny (239B) utility for constructing className strings conditionally.
@emotion/memoize 0.6.6 - 0.7.4Outdated
emotion's memoize utility
+1
emmatown
tkh44
emotion-release-bot
setimmediate 1.0.5
A shim for the setImmediate efficient script yielding API
domenic
domenic
hoist-non-react-statics 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
ecdsa-sig-formatter 1.0.10 - 1.0.11
Translate ECDSA signatures between ASN.1/DER and JOSE-style concatenation
d2l-travis-deploy
d2l-travis-deploy
buffer-equal-constant-time 1.0.0 - 1.0.1
Constant-time comparison of Buffers
invariant 2.2.3 - 2.2.4
invariant
@emotion/unitless 0.7.2 - 0.7.5Outdated
An object of css properties that don't accept values with units
+1
emmatown
tkh44
emotion-release-bot
promise 8.2.0Outdated
Bare bones Promises/A+ implementation
forbeslindesay
then-promise-bot
lodash.once 4.1.1
The lodash method `_.once` exported as a module.
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
lodash.isstring 4.0.1
The lodash method `_.isString` exported as a module.
stylis 4.0.13Outdated
A Light–weight CSS Preprocessor
andarist
thysultan
react-transition-group 4.4.0 - 4.4.2Outdated
A react component toolset for managing animations
@emotion/hash 0.8.0Outdated
A MurmurHash2 implementation
+1
emmatown
tkh44
emotion-release-bot
dom-helpers 3.4.0Outdated
tiny modular DOM lib for ie9+
sha.js 2.4.10 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
whatwg-fetch 3.6.2Outdated
A window.fetch polyfill.
jakechampion
mattandrews
mislav
@emotion/serialize 0.11.14 - 0.11.16Outdated
serialization utils for emotion
+1
emmatown
tkh44
emotion-release-bot
@emotion/utils 0.11.0 - 0.11.3Outdated
internal utils for emotion
+1
emmatown
tkh44
emotion-release-bot
lodash.isboolean 3.0.3
The lodash method `_.isBoolean` exported as a module.
stream-browserify 1.0.0 - 2.0.2Outdated
the stream module from node core for browsers
tiny-invariant 1.2.0Outdated
A tiny invariant function
memoize-one 4.1.0Outdated
A memoization library which only remembers the latest invocation
asn1.js 5.3.0 - 5.4.1
ASN.1 encoder and decoder
lodash.includes 4.3.0
The lodash method `_.includes` exported as a module.
@emotion/cache 10.0.17 - 10.0.29Outdated
emotion's cache
+1
emmatown
tkh44
emotion-release-bot
elliptic 6.5.4Outdated
EC cryptography
hash-base 3.1.0
abstract base class for hash-streams
lodash.isinteger 4.0.4
The lodash method `_.isInteger` exported as a module.
@emotion/sheet 0.9.1 - 0.9.4Outdated
emotion's stylesheet
+1
emmatown
tkh44
emotion-release-bot
lodash.isnumber 3.0.3
The lodash method `_.isNumber` exported as a module.
hash.js 1.1.7
Various hash functions that could be run by both browser and node
react-router 5.2.1Outdated
Declarative routing for React
is-promise 2.2.0 - 4.0.0
Test whether an object looks like a promises-a+ promise
forbeslindesay
then-bot
brorand 1.1.0
Random number generator for browsers and node.js
react-router-dom 5.3.0 - 5.3.3Outdated
Declarative routing for React web applications
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
minimalistic-crypto-utils 1.0.1
Minimalistic tools for JS crypto modules
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
lodash-es 4.17.20 - 4.17.21
Lodash exported as ES modules.
redux 4.2.0Outdated
Predictable state container for JavaScript apps
des.js 1.0.1Outdated
DES implementation
warning 4.0.3
A mirror of Facebook's Warning
ripemd160 2.0.2
Compute ripemd160 of bytes or strings.
pbkdf2 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
md5.js 1.3.5
node style md5 on pure JavaScript
parse-asn1 5.1.6Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
cipher-base 1.0.4
abstract base class for crypto-streams
buffer-xor 1.0.0 - 1.0.3Outdated
A simple module for bitwise-xor on buffers
create-hash 1.2.0
create hashes for browserify
browserify-aes 1.2.0
aes, for browserify
create-hmac 1.1.6 - 1.1.7
node style hmacs in the browser
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 4.1.0
RSA for browserify
+2
dcousens
ljharb
cwmma
timers-browserify 2.0.10 - 2.0.12
timers module for browserify
crypto-browserify 3.12.0
implementation of crypto for the browser
+2
dcousens
ljharb
cwmma
create-ecdh 4.0.2 - 4.0.4
createECDH but browserifiable
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
diffie-hellman 5.0.2 - 5.0.3
pure js diffie-hellman
browserify-des 1.0.2
browserify-des ===
dcousens
ljharb
cwmma
browserify-cipher 1.0.1
ciphers for the browser
cwmma
cwmma
miller-rabin 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.3 - 1.0.4
random fill from browserify stand alone
mdurl 1.0.1Outdated
URL utilities for markdown-it
vitaly
vitaly
@emotion/react 11.0.0 - 11.10.5Outdated
> Simple styling in React.
+1
emmatown
tkh44
emotion-release-bot
shallowequal 1.1.0
Like lodash isEqualWith but for shallow equal.
react-redux 5.1.2Outdated
Official React bindings for Redux
tiny-warning 1.0.2 - 1.0.3
A tiny warning function
alexreardon
alexreardon
fbjs 0.8.16 - 0.8.18Outdated
A collection of utility libraries used by other Facebook JS projects
+5
zpao
eliwhite
yungsters
linkify-it 2.2.0Outdated
Links recognition library with FULL unicode support
history 4.10.1Outdated
Manage session history with JavaScript
uc.micro 1.0.6Outdated
Micro subset of unicode data files for markdown-it projects.
vitaly
vitaly
p-defer 1.0.0 - 4.0.0Outdated
Create a deferred promise
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
fb
sophiebits
resize-observer-polyfill 1.5.1
A polyfill for the Resize Observer API
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
react-select 4.3.0 - 4.3.1Outdated
A Select control built with and for ReactJS
@emotion/stylis 0.8.4 - 0.8.5
A custom build of Stylis
+1
emmatown
tkh44
emotion-release-bot
es6-error 4.0.1 - 4.1.1
Easily-extendable error for use with ES6 classes
resolve-pathname 3.0.0
Resolve URL pathnames using JavaScript
mjackson
mjackson
value-equal 1.0.1
Are these two JavaScript values equal?
mjackson
mjackson
hyphenate-style-name 1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
@mui/material 5.0.0 - 5.10.11Outdated
Material UI is an open-source React component library that implements Google's Material Design. It's comprehensive and can be used in production out of the box.
react-app-polyfill 2.0.0 - 3.0.0
Polyfills for various browsers including commonly used language features
+1
fb
timer
iansu
@apollo/client 3.0.0 - 3.7.1Outdated
A fully-featured caching GraphQL client.
rc-util 5.19.6 - 5.21.5Outdated
Common Utils For React Component
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
@emotion/css 10.0.0 - 10.0.27Outdated
The Next Generation of CSS-in-JS.
uncontrollable 7.2.1Outdated
Wrap a controlled react component, to allow specific prop/handler pairs to be uncontrolled
inline-style-prefixer 3.0.8Outdated
Run-time Autoprefixer for JavaScript style objects
@emotion/core 10.3.0 - 10.3.1Outdated
+1
emmatown
tkh44
emotion-release-bot
jss 10.0.0 - 10.9.2Outdated
A lib for generating Style Sheets with JavaScript.
css-in-js-utils 2.0.0 - 3.0.2Outdated
Useful utility functions for CSS in JS solutions
react-input-autosize 3.0.0
Auto-resizing Input Component for React
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
is-in-browser 1.1.3Outdated
Simple check to see if current app is running in browser
tuxsudo
tuxsudo
string-convert 0.1.0 - 0.2.1
String convertions
akiran
akiran
json2mq 0.2.0
Generate media query string from JSON or javascript object
akiran
akiran
react-icons 4.2.0Outdated
SVG React icons of popular icon packs using ES6 imports
+2
nwwells
tusbar
gorangajic
css-vendor 2.0.8
CSS vendor prefix detection and property feature testing.
jss-plugin-nested 10.9.0Outdated
JSS plugin that enables support for nested selectors
jss-plugin-global 10.9.0Outdated
Global styles for JSS
jss-plugin-camel-case 10.8.0 - 10.9.0Outdated
JSS plugin that allows to write camel cased rule properties
jss-plugin-default-unit 10.8.0 - 10.9.0Outdated
JSS plugin that adds default custom unit to numeric values where needed
mini-create-react-context 0.3.3 - 0.4.1
Smaller Polyfill for the proposed React context API
jss-plugin-rule-value-function 10.8.0 - 10.9.0Outdated
JSS plugin for function value and rule syntax
jss-plugin-vendor-prefixer 10.8.0 - 10.9.0Outdated
JSS plugin that handles vendor prefixes in the browser
jss-plugin-props-sort 10.0.0 - 10.9.0Outdated
JSS plugin that ensures style properties extend each other instead of override
react-side-effect 2.1.0Outdated
Create components whose prop changes map to a global side effect
math-random 1.0.2 - 1.0.4Outdated
math-random is an isomorphic, drop-in replacement for `Math.random` that uses cryptographically secure random number generation, where available
michaelrhodes
michaelrhodes
react-helmet 6.1.0
A document head manager for React
react-overlays 0.9.3Outdated
Utilities for creating robust overlay components
prop-types-extra 1.1.0 - 1.1.1
React PropType Utilities
monastic.panic
monastic.panic
rc-motion 2.6.0Outdated
React lifecycle controlled motion library
react-bootstrap 0.33.1Outdated
Bootstrap 5 components built with React
@material-ui/utils 4.11.3
Material-UI Utils - Utility functions for Material-UI.
rc-trigger 4.3.0 - 4.3.4Outdated
base abstract trigger component for react
@material-ui/core 4.12.3Outdated
React components that implement Google's Material Design.
load-script 1.0.0 - 2.0.0
Dynamic script loading for browser
@material-ui/system 4.11.3 - 4.12.2
Material-UI System - Design system for Material-UI.
@material-ui/styles 4.11.1 - 4.11.5
Material-UI Styles - The styling solution of Material-UI.
rc-collapse 3.1.2 - 3.1.4Outdated
rc-collapse ui component for react
nprogress 0.2.0
Simple slim progress bars
rstacruz
rstacruz
enquire.js 2.1.6
Awesome Media Queries in JavaScript
mobx-react-lite 2.2.0 - 3.0.1Outdated
Lightweight React bindings for MobX based on React 16.8+ and Hooks
redux-saga 0.16.1 - 0.16.2Outdated
Saga middleware for Redux to handle Side Effects
keycode 2.2.0Outdated
Convert between keyboard keycodes and keynames and vice versa.
react-slick 0.28.1Outdated
React port of slick carousel
react-player 2.9.0Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
@babel/runtime-corejs2 7.18.2 - 7.19.2Outdated
babel's modular runtime helpers with core-js@2 polyfilling
+1
hzoo
existentialism
nicolo-ribaudo
@chakra-ui/theme 2.1.0 - 2.1.3Outdated
The default theme for chakra components
react-loading-skeleton 2.2.0Outdated
Make beautiful, animated loading skeletons that automatically adapt to your app.
react-share 4.3.0 - 4.4.0Outdated
Social media share buttons and share counts for React.
connected-react-router 6.9.0 - 6.9.2Outdated
A Redux binding for React Router v4 and v5
supasate
supasate
lodash.isequalwith 4.4.0
The lodash method `_.isEqualWith` exported as a module.
redux-form 8.3.6 - 8.3.8Outdated
A higher order component decorator for forms using Redux and React
bootstrap-vue 2.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
use-query-params 2.0.0 - 2.1.2Outdated
React Hook for managing state in URL query parameters with easy serialization.
react-html-parser 2.0.2
Parse HTML into React components
react-google-recaptcha-v3 1.9.1 - 1.9.8Outdated
React component for google-recaptcha v3
duongtran
duongtran
lazysizes 5.3.1 - 5.3.2
High performance (jankfree) lazy loader for images (including responsive images), iframes and scripts (widgets).
redux-observable 2.0.0Outdated
RxJS based middleware for Redux. Compose and cancel async actions and more.
loadjs 4.2.0Outdated
Tiny async loader for modern browsers
@analytics/storage-utils 0.2.5 - 0.2.14Outdated
Storage utility with fallbacks
deepcopy 2.0.0 - 2.1.0
deep copy data
sasaplus1
sasaplus1
react-truncate 2.4.0
React component for truncating multi-line spans and adding an ellipsis
react-collapsible 2.8.4Outdated
React component to wrap content in Collapsible element with trigger to open and close.
adaptivecards 1.1.3Outdated
Adaptive Cards Javascript library for HTML Clients
jump.js 1.0.1Outdated
A modern smooth scrolling library.
callmecavs
callmecavs
redux-promise-middleware 5.1.1Outdated
Enables simple, yet robust handling of async action creators in Redux
glamor 2.20.40
inline css for component systems
simple-update-in 1.4.0Outdated
A lightweight `updateIn` for immutable objects.
react-scroll-to-bottom 1.2.0 - 4.2.0
React container that will auto scroll to bottom
markdown-it-for-inline 0.1.1Outdated
Inline tokens iterator for markdown-it markdown parser.
botframework-directlinejs 0.11.6Outdated
Client library for the Microsoft Bot Framework Direct Line 3.0 protocol
+5
botframework
sgellock
cwhitten
react-scrollable-anchor 0.6.1
Provide smooth scrolling anchors in React.
botframework-webchat 4.4.1 - 4.4.2Outdated
A highly-customizable web-based chat client for Azure Bot Services.
+5
botframework
sgellock
cwhitten
event-as-promise 1.0.0 - 1.0.2Outdated
Handle continuous stream of events with Promise and generator function.
web-speech-cognitive-services 4.0.0Outdated
Polyfill Web Speech API with Cognitive Services Speech-to-Text service
react-film 1.0.0 - 2.1.0Outdated
React component for showing carousel just like a film strip
botframework-webchat-core 4.4.1Outdated
Core of botframework-webchat
+2
botframework
sgellock
cwhitten
react-say 1.2.0Outdated
[![npm version](https://badge.fury.io/js/react-say.svg)](https://badge.fury.io/js/react-say) [![Build Status](https://travis-ci.org/compulim/react-say.svg?branch=master)](https://travis-ci.org/compulim/react-say)
botframework-webchat-component 4.4.1 - 4.4.2Outdated
React component of botframework-webchat
+2
botframework
sgellock
cwhitten
react-dictate-button 1.2.0 - 1.2.2Outdated
A button to start dictation using Web Speech API, with an easy to understand event lifecycle.
@dhmk/utils 1.0.0Outdated
A collection of frequently used functions and primitives
microsoft-speech-browser-sdk 0.0.12
Microsoft Speech SDK for browsers
@rooks/use-fork-ref 3.4.0 - 4.11.2
A hook that can combine two refs(mutable or callbackRefs) into a single callbackRef
react-structured-data x.x.x
remove-stopwords x.x.x
react-sweet-progress x.x.x
react-twitter-widgets x.x.x
@emotion/use-insertion-effect-with-fallbacks x.x.x
chop-lines x.x.x
react-show-more x.x.x
@material-ui/lab x.x.x