coveredca.com 160 packages

Last scanned on Jan 19 at 09:34 AM
lodash.mergewith 4.6.1VulnerableOutdated
The Lodash method `_.mergeWith` exported as a module.
License
MIT
Vulnerabilities
Prototype Pollution in lodash
Affected versions >=0 <4.6.2
Prototype Pollution in lodash.mergewith
Affected versions >=0 <4.6.2
Version distribution in production
113
4.6.2
72
4.6.1
0
4.0.0
0
4.0.1
0
4.0.2
0
4.0.3
jsonwebtoken 8.5.0 - 8.5.1VulnerableOutdated
JSON Web Token implementation (symmetric and asymmetric)
elliptic 6.3.1 - 6.4.1VulnerableOutdated
EC cryptography
sanitize-html 1.20.1VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
postcss 4.1.3 - 7.0.39VulnerableOutdated
Tool for transforming styles with JS plugins
markdown-it 8.4.1 - 8.4.2VulnerableOutdated
Markdown-it - modern pluggable markdown parser.
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
semver 5.6.0 - 6.3.0Outdated
The semantic version parser used by npm.
+2
npm-cli-ops
saquibkhan
fritzy
ms 2.1.2 - 2.1.3
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
source-map 0.6.1Outdated
Generates and consumes source maps
+16
tigleym
nbaumgardner
eemeli
readable-stream 2.3.4 - 2.3.7Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
safe-buffer 5.1.0 - 5.2.1
Safer Node.js Buffer API
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
punycode x.x.x
A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.
inherits 2.0.3Outdated
Browser-friendly inheritance fully compatible with standard node.js inherits()
mime 2.4.3Outdated
A comprehensive library for mime-type mapping
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
regenerator-runtime x.x.x
Runtime for Regenerator-compiled generator and async functions.
bytes 3.0.0Outdated
Utility to parse a string bytes to bytes and vice-versa
entities 1.1.1 - 1.1.2Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.18.2 - 7.18.3Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
rxjs 5.5.12Outdated
Reactive Extensions for modern JavaScript
ieee754 1.1.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
util-deprecate x.x.x
The Node.js `util.deprecate()` function with browser support
object-assign 4.1.0 - 4.1.1
ES2015 `Object.assign()` ponyfill
domutils 1.7.0Outdated
Utilities for working with htmlparser2's dom
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
dom-serializer 0.1.1Outdated
render domhandler DOM nodes to a string
domhandler 2.4.0 - 2.4.2Outdated
Handler for htmlparser2 that turns pages into a dom
bn.js x.x.x
Big number implementation in pure javascript
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
domelementtype 1.2.0 - 1.3.1Outdated
all the types of nodes in htmlparser2's dom
process-nextick-args 2.0.0 - 2.0.1
process.nextTick but always with args
cwmma
cwmma
core-js 3.0.1Outdated
Standard library
util 0.10.0 - 0.12.5
Node.js's util module for all engines
htmlparser2 3.10.0 - 3.10.1Outdated
Fast & forgiving HTML/XML parser
xtend 4.0.1 - 4.0.2
extend like a boss
scheduler 0.19.0 - 0.19.1Outdated
Cooperative scheduler for the browser environment.
randombytes x.x.x
random bytes from browserify stand alone
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 17.0.0 - 17.0.2Outdated
React is a JavaScript library for building user interfaces.
process x.x.x
process information for node.js and browsers
jws 3.2.1 - 4.0.0
Implementation of JSON Web Signatures
jwa 1.4.1Outdated
JWA implementation (supports all JWS algorithms)
react-dom 16.13.0 - 16.14.0Outdated
React package for working with the DOM.
performance-now 0.1.3 - 2.1.0
Implements performance.now (based on process.hrtime).
meryn
meryn
url 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
lodash.isplainobject 4.0.6
The lodash method `_.isPlainObject` exported as a module.
asap x.x.x
High-priority task queue for Node.js and browsers
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
setimmediate x.x.x
A shim for the setImmediate efficient script yielding API
domenic
domenic
html-entities 2.0.4 - 2.3.3Outdated
Fastest HTML entities encode/decode library.
hoist-non-react-statics 3.3.0Outdated
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
ecdsa-sig-formatter 1.0.10 - 1.0.11
Translate ECDSA signatures between ASN.1/DER and JOSE-style concatenation
d2l-travis-deploy
d2l-travis-deploy
buffer-equal-constant-time 1.0.0 - 1.0.1
Constant-time comparison of Buffers
invariant 2.2.0 - 2.2.4
invariant
path-browserify 0.0.0 - 0.0.1Outdated
the path module from node core for browsers
promise 8.0.2 - 8.0.3Outdated
Bare bones Promises/A+ implementation
forbeslindesay
then-promise-bot
lodash.once 4.1.1
The lodash method `_.once` exported as a module.
dequal 2.0.0 - 2.0.3
A tiny (304B to 489B) utility for check for deep equality
lodash.isstring 4.0.1
The lodash method `_.isString` exported as a module.
classnames 2.3.2Outdated
A simple utility for conditionally joining classNames together
symbol-observable 1.2.0Outdated
Symbol.observable ponyfill
react-transition-group 4.1.0 - 4.4.5
A react component toolset for managing animations
sha.js 2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
whatwg-fetch 3.0.0 - 3.1.1Outdated
A window.fetch polyfill.
jakechampion
mattandrews
mislav
dom-helpers 5.2.1
tiny modular DOM lib for ie9+
lodash.isboolean 3.0.1 - 3.0.3
The lodash method `_.isBoolean` exported as a module.
stream-browserify 0.0.0 - 3.0.0
the stream module from node core for browsers
@popperjs/core 2.11.3 - 2.11.5Outdated
Tooltip and Popover Positioning Engine
asn1.js 4.6.0 - 4.10.1Outdated
ASN.1 encoder and decoder
lodash.includes 4.3.0
The lodash method `_.includes` exported as a module.
hash-base 3.0.4 - 3.1.0
abstract base class for hash-streams
lodash.isinteger 4.0.4
The lodash method `_.isInteger` exported as a module.
lodash.clonedeep 4.5.0
The lodash method `_.cloneDeep` exported as a module.
lodash.isnumber 3.0.1 - 3.0.3
The lodash method `_.isNumber` exported as a module.
memoize-one 4.0.2 - 4.0.3Outdated
A memoization library which only remembers the latest invocation
hash.js 1.1.2 - 1.1.7
Various hash functions that could be run by both browser and node
brorand 1.0.3 - 1.1.0
Random number generator for browsers and node.js
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
minimalistic-crypto-utils x.x.x
Minimalistic tools for JS crypto modules
redux 4.0.1 - 4.2.0Outdated
Predictable state container for JavaScript apps
des.js 1.0.0Outdated
DES implementation
ripemd160 2.0.0 - 2.0.2
Compute ripemd160 of bytes or strings.
number-is-nan 1.0.0 - 1.0.1Outdated
ES2015 `Number.isNaN()` ponyfill
array-uniq 0.1.1 - 1.0.3Outdated
Create an array without duplicates
warning 1.0.0 - 4.0.3
A mirror of Facebook's Warning
md5.js 1.1.0 - 1.3.5
node style md5 on pure JavaScript
pbkdf2 3.0.16 - 3.0.17Outdated
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
cipher-base 1.0.4
abstract base class for crypto-streams
parse-asn1 5.1.4 - 5.1.5Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
browserify-sign 2.4.0 - 2.8.0Outdated
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
buffer-xor 1.0.0 - 1.0.3Outdated
A simple module for bitwise-xor on buffers
create-hash x.x.x
create hashes for browserify
browserify-aes 0.4.0 - 0.8.1Outdated
aes, for browserify
create-hmac x.x.x
node style hmacs in the browser
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 3.0.0 - 4.0.1Outdated
RSA for browserify
+2
dcousens
ljharb
cwmma
timers-browserify 2.0.6 - 2.0.12
timers module for browserify
crypto-browserify x.x.x
implementation of crypto for the browser
+2
dcousens
ljharb
cwmma
create-ecdh 3.0.0 - 4.0.4
createECDH but browserifiable
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
diffie-hellman 1.1.2Outdated
pure js diffie-hellman
browserify-des 1.0.2
browserify-des ===
dcousens
ljharb
cwmma
browserify-cipher x.x.x
ciphers for the browser
cwmma
cwmma
miller-rabin 1.1.0 - 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.0 - 1.0.4
random fill from browserify stand alone
vm-browserify 0.0.3 - 1.1.2
vm module for the browser
mdurl 1.0.0 - 1.0.1Outdated
URL utilities for markdown-it
vitaly
vitaly
character-entities-legacy 2.0.0Outdated
List of legacy HTML named character references that don’t need a trailing semicolon
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
react-redux 5.1.0 - 5.1.1Outdated
Official React bindings for Redux
linkify-it 2.1.0Outdated
Links recognition library with FULL unicode support
fbjs 1.0.0 - 3.0.4Outdated
A collection of utility libraries used by other Facebook JS projects
+5
zpao
eliwhite
yungsters
@xmldom/xmldom 0.7.0 - 0.8.6Outdated
A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
raf 3.2.0 - 3.4.1
requestAnimationFrame polyfill for node and the browser
uc.micro 1.0.6Outdated
Micro subset of unicode data files for markdown-it projects.
vitaly
vitaly
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
fb
sophiebits
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
hyphenate-style-name 1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
lodash.escaperegexp 4.1.2
The lodash method `_.escapeRegExp` exported as a module.
react-app-polyfill x.x.x
Polyfills for various browsers including commonly used language features
+1
fb
timer
iansu
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
inline-style-prefixer 0.1.1 - 4.0.2Outdated
Run-time Autoprefixer for JavaScript style objects
css-in-js-utils 1.0.0 - 3.0.2Outdated
Useful utility functions for CSS in JS solutions
uncontrollable 7.1.0 - 7.2.1Outdated
Wrap a controlled react component, to allow specific prop/handler pairs to be uncontrolled
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
math-random x.x.x
math-random is an isomorphic, drop-in replacement for `Math.random` that uses cryptographically secure random number generation, where available
michaelrhodes
michaelrhodes
react-dnd 9.1.0 - 9.3.4Outdated
Drag and Drop for React
+2
jordangens
gaearon
darthtrevino
@restart/hooks 0.4.6 - 0.4.7Outdated
A set of utility and general-purpose React hooks.
monastic.panic
taion
kytsang
react-bootstrap 2.0.0 - 2.4.0Outdated
Bootstrap 5 components built with React
redux-saga 0.16.1 - 0.16.2Outdated
Saga middleware for Redux to handle Side Effects
leaflet 1.3.2 - 1.9.1Outdated
JavaScript library for mobile-friendly interactive maps
react-player 1.12.0 - 1.15.3Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
react-async-script 1.2.0
A composition mixin for loading scripts asynchronously for React
react-google-recaptcha 2.1.0Outdated
React Component Wrapper for Google reCAPTCHA
react-input-mask 2.0.4
Masked input component for React
@restart/ui 1.4.0 - 1.4.1Outdated
Utilities for creating robust overlay components
srcset 1.0.0Outdated
Parse and stringify the HTML `<img>` srcset attribute
custom-event-polyfill x.x.x
A polyfill for creating CustomEvents on IE9+ if the native implementation is missing.
adaptivecards 1.1.1 - 1.1.3Outdated
Adaptive Cards Javascript library for HTML Clients
redux-promise-middleware 5.0.0 - 5.1.1Outdated
Enables simple, yet robust handling of async action creators in Redux
glamor 2.20.37 - 2.20.40
inline css for component systems
simple-update-in 1.4.0 - 2.2.0
A lightweight `updateIn` for immutable objects.
react-scroll-to-bottom 1.3.1Outdated
React container that will auto scroll to bottom
markdown-it-for-inline 0.1.1Outdated
Inline tokens iterator for markdown-it markdown parser.
botframework-directlinejs 0.11.4Outdated
Client library for the Microsoft Bot Framework Direct Line 3.0 protocol
+5
botframework
sgellock
cwhitten
botframework-webchat 4.4.2Outdated
A highly-customizable web-based chat client for Azure Bot Services.
+5
botframework
sgellock
cwhitten
event-as-promise 1.0.5
Handle continuous stream of events with Promise and generator function.
web-speech-cognitive-services 4.0.0Outdated
Polyfill Web Speech API with Cognitive Services Speech-to-Text service
botframework-webchat-core 4.4.1 - 4.4.2Outdated
Core of botframework-webchat
+2
botframework
sgellock
cwhitten
botframework-webchat-component 4.4.2Outdated
React component of botframework-webchat
+2
botframework
sgellock
cwhitten
react-film 1.2.0 - 1.3.0Outdated
React component for showing carousel just like a film strip
react-say 1.2.0Outdated
[![npm version](https://badge.fury.io/js/react-say.svg)](https://badge.fury.io/js/react-say) [![Build Status](https://travis-ci.org/compulim/react-say.svg?branch=master)](https://travis-ci.org/compulim/react-say)
react-dictate-button 1.1.2 - 1.1.3Outdated
A button to start dictation using Web Speech API, with an easy to understand event lifecycle.
@dhmk/utils 1.0.0Outdated
A collection of frequently used functions and primitives
microsoft-speech-browser-sdk 0.0.12
Microsoft Speech SDK for browsers