About
Community
citypass.com
41 packages
Last scanned on Jan 19 at 08:55 AM
Update
Name
Size
Popularity
Severity
lodash
4.17.16
Vulnerable
Outdated
Lodash modular utilities.
Script
https://s1.citypass.net/_next/static/chunks/pages/_app-206864243b6e3283.js
https://s1.citypass.net/_next/static/chunks/3894-9462c86e73fd9972.js
License
MIT
Footprint
6 KB
Vulnerabilities
High
GHSA-35jh-r3h4-6jhm
Command Injection in lodash
Affected versions >=0 <4.17.21
Moderate
GHSA-29mw-wpgm-hmr9
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
High
GHSA-p6mc-m468-83gw
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
Also used on 4830 websites
skype.com
20 packages
sentry.io
157 packages
pinterest.com
56 packages
pinimg.com
52 packages
Repository
Homepage
More
modules
stdlib
util
next
12.1.0 - 12.1.5
Vulnerable
Outdated
The React Framework
@babel/runtime
7.13.6 - 7.13.7
Outdated
babel's modular runtime helpers
+1
get-intrinsic
1.1.0 - 1.1.1
Outdated
Get and robustly cache all JS language-level intrinsics at first require time
javascript
ecmascript
es
js
intrinsic
+2
ljharb
function-bind
1.1.0 - 1.1.1
Outdated
Implementation of Function.prototype.bind
function
bind
shim
es5
path-to-regexp
6.1.0 - 6.2.0
Outdated
Express style path to RegExp utility
express
regexp
route
routing
+2
axios
0.24.0
Outdated
Promise based HTTP client for the browser and node.js
xhr
http
ajax
promise
node
+1
call-bind
1.0.2
Outdated
Robustly `.call.bind()` a function
javascript
ecmascript
es
js
callbind
+8
ljharb
object-inspect
1.9.0 - 1.11.1
Outdated
string representations of objects in node and the browser
inspect
util.inspect
object
stringify
pretty
has-symbols
1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
Symbol
symbols
typeof
sham
polyfill
+3
ljharb
side-channel
1.0.4
Outdated
Store information about any JS value in a side channel. Uses WeakMap if available.
weakmap
map
side
channel
metadata
ljharb
es-abstract
1.19.0 - 1.19.1
Outdated
ECMAScript spec abstract operations.
ECMAScript
ES
abstract
operation
abstract operation
+4
ljharb
define-properties
1.1.3 - 1.1.4
Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
Object.defineProperty
Object.defineProperties
object
property descriptor
descriptor
+2
ljharb
is-callable
1.2.3 - 1.2.4
Outdated
Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.
Function
function
callable
generator
generator function
+5
ljharb
has-tostringtag
1.0.0
Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
javascript
ecmascript
symbol
symbols
tostringtag
+1
ljharb
object-keys
1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
Object.keys
keys
ES5
shim
ljharb
regexp.prototype.flags
1.2.0 - 1.3.2
Outdated
ES6 spec-compliant RegExp.prototype.flags shim.
RegExp.prototype.flags
regex
regular expression
ES6
shim
+6
ljharb
deepmerge
4.2.2
Outdated
A library for deep (recursive) merging of Javascript objects
merge
deep
extend
copy
clone
+1
tehshrike
is-regex
1.1.4
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
regex
regexp
is
regular expression
regular
+1
ljharb
internal-slot
1.0.1 - 1.0.3
Outdated
ES spec-like internal slots
internal
slot
internal slot
ecmascript
es
+5
ljharb
is-date-object
1.0.1 - 1.0.3
Outdated
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
Date
ES6
toStringTag
@@toStringTag
Date object
ljharb
es-to-primitive
1.2.0 - 1.2.1
ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.
primitive
abstract
ecmascript
es5
es6
+11
ljharb
scheduler
0.15.0 - 0.23.0
Outdated
Cooperative scheduler for the browser environment.
react
+1
has
1.0.1 - 1.0.3
Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
prop-types
15.7.0 - 15.7.2
Outdated
Runtime type checking for React props and similar objects.
react
react
17.0.0 - 18.2.0
Outdated
React is a JavaScript library for building user interfaces.
react
+1
dayjs
1.10.6 - 1.10.8
Outdated
2KB immutable date time library alternative to Moment.js with the same modern API
dayjs
date
time
immutable
moment
iamkun
clsx
1.2.0 - 1.2.1
Outdated
A tiny (239B) utility for constructing className strings conditionally.
classes
classname
classnames
lukeed
string.prototype.matchall
4.0.6
Outdated
Spec-compliant polyfill for String.prototype.matchAll
ES2020
ES
String.prototype.matchAll
matchAll
match
+5
ljharb
classnames
2.2.6
Outdated
A simple utility for conditionally joining classNames together
react
css
classes
classname
classnames
+2
lodash-es
4.17.21
Lodash exported as ES modules.
es6
modules
stdlib
util
quick-format-unescaped
4.0.3
Outdated
Solves a problem with util.format
davidmarkclements
js-base64
3.2.0 - 3.3.3
Outdated
Yet another Base64 transcoder in pure-JS
base64
binary
dankogai
use-subscription
1.3.0 - 1.5.1
Outdated
Reusable hooks
+1
smoothscroll-polyfill
0.4.4
Smooth Scroll behavior polyfill
smooth
scroll
CSSOM
polyfill
react-gtm-module
2.0.9 - 2.0.11
React Google Tag Manager Module
react
reactjs
react-component
google tag manager
tag manager
+1
alinemorelli
react-animate-height
2.0.16 - 2.1.0
Outdated
Lightweight React component for animating height using CSS transitions.
react
react-component
slide
slide up
slide down
+1
stanko.tadic
@bugsnag/plugin-react
7.2.1 - 7.18.0
Outdated
React integration for @bugsnag/js
+6
react-lazyload
2.4.0 - 3.2.0
Outdated
Lazyload your components, images or anything where performance matters.
react-component
react
lazyload
+1
react-facebook
4.1.1 - 5.0.3
Outdated
Facebook components like a Login button, Like, Share, Comments, Embedded Post/Video, Messenger Chat and others
react
react-component
facebook
login
login button
+12
zlatkofedor
react-amphtml
3.1.0 - 4.0.2
Use amphtml components inside your React apps easily!
react
amphtml
dfrankland
Popular search queries
webpack.js.org
url
react-scripts
react
lottie-api
react-helmet-async
+7 packages
github.com
color-convert
@headlessui/react
hoist-non-react-statics
reactstrap
lit-html
+60 packages
pinterest.com
lodash
relay-runtime
react-relay
react-use
lodash-es
+51 packages
Popular packages
react
React is a JavaScript library for building user interfaces.
+6 634 websites
core-js
Standard library
+10 238 websites
es5-ext
ECMAScript extensions and shims
+10 229 websites
@babel/runtime
babel's modular runtime helpers
+8 352 websites
lodash
Lodash modular utilities.
+4 826 websites
axios
Promise based HTTP client for the browser and node.js
+4 742 websites