glose.com 151 packages

Last scanned on Jan 19 at 12:45 PM
url-parse 1.4.5 - 1.4.7VulnerableOutdated
Small footprint URL parser that works seamlessly across Node.js and browser environments
License
MIT
Footprint
3 KB
Vulnerabilities
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
Affected versions >=0 <1.5.9
Authorization bypass in url-parse
Affected versions >=0 <1.5.6
Path traversal in url-parse
Affected versions >=0 <1.5.0
Open redirect in url-parse
Affected versions >=0 <1.5.2
Authorization Bypass Through User-Controlled Key in url-parse
Affected versions >=0 <1.5.8
url-parse Incorrectly parses URLs that include an '@'
Affected versions >=0 <1.5.7
Matched Modules
Version distribution in production
206
1.5.10
167
1.5.9
50
1.5.3
47
1.4.6
47
1.4.7
24
1.5.4
lodash-es 4.10.0VulnerableOutdated
Lodash exported as ES modules.
d3-color 1.0.2 - 1.3.0VulnerableOutdated
Color spaces! RGB, HSL, Cubehelix, Lab and HCL (Lch).
markdown-it 2.0.0 - 3.1.0VulnerableOutdated
Markdown-it - modern pluggable markdown parser.
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
next 7.0.0 - 13.1.2VulnerableOutdated
The React Framework
rauchg
timneutkens
vercel-release-bot
sweetalert2 9.3.1VulnerableOutdated
A beautiful, responsive, customizable and accessible (WAI-ARIA) replacement for JavaScript's popup boxes, supported fork of sweetalert
readable-stream 2.3.4 - 2.3.7Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
isarray 0.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
inherits 2.0.3Outdated
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
balanced-match 0.4.2 - 1.0.0Outdated
Match balanced character pairs, like "{" and "}"
entities 1.0.0 - 1.1.2Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.0.0 - 7.12.18Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
path-to-regexp 1.7.0 - 1.8.0Outdated
Express style path to RegExp utility
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
has-symbols 1.0.0 - 1.0.1Outdated
Determine if the JS environment has Symbol support. Supports spec, or shams.
object-assign 3.0.0Outdated
ES2015 `Object.assign()` ponyfill
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
es-abstract 1.13.0Outdated
ECMAScript spec abstract operations.
define-properties 1.1.3 - 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
is-callable 1.1.4 - 1.1.5Outdated
Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.
domhandler 2.4.0 - 2.4.2Outdated
Handler for htmlparser2 that turns pages into a dom
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
object-keys 1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
deepmerge 1.5.2Outdated
A library for deep (recursive) merging of Javascript objects
domelementtype 1.2.0 - 1.3.1Outdated
all the types of nodes in htmlparser2's dom
core-js 2.6.11Outdated
Standard library
is-regex 1.0.4 - 1.0.5Outdated
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
is-date-object 1.0.1 - 1.0.3Outdated
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
util 0.10.0 - 0.12.5
Node.js's util module for all engines
es-to-primitive 1.2.0 - 1.2.1
ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.
htmlparser2 3.10.0 - 3.10.1Outdated
Fast & forgiving HTML/XML parser
object.values 1.0.0 - 1.1.6Outdated
ES2017 spec-compliant Object.values shim.
scheduler 0.9.0 - 0.23.0Outdated
Cooperative scheduler for the browser environment.
requires-port 1.0.0
Check if a protocol requires a certain port number to be added to an URL.
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
array.prototype.flat 1.2.1Outdated
An ES2019 spec-compliant `Array.prototype.flat` shim/polyfill/replacement that works as far down as ES3.
prop-types 15.7.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 17.0.0 - 18.2.0Outdated
React is a JavaScript library for building user interfaces.
react-dom 18.0.0 - 18.2.0Outdated
React package for working with the DOM.
querystringify 2.1.1Outdated
Querystringify - Small, simple but powerful query string parser.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
performance-now 0.1.3 - 2.1.0
Implements performance.now (based on process.hrtime).
meryn
meryn
url 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
date-fns 2.0.0 - 2.6.0Outdated
Modern JavaScript date utility library
kossnocorp
kossnocorp
clsx 1.0.4Outdated
A tiny (239B) utility for constructing className strings conditionally.
html-entities 2.0.4 - 2.3.3Outdated
Fastest HTML entities encode/decode library.
hoist-non-react-statics 2.5.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
classnames 2.2.6Outdated
A simple utility for conditionally joining classNames together
lodash.camelcase 4.2.0 - 4.3.0
The lodash method `_.camelCase` exported as a module.
common-tags 1.4.0 - 1.8.2
a few common utility template tags for ES2015
react-transition-group 2.4.0 - 3.0.0Outdated
A react component toolset for managing animations
ramda 0.26.0 - 0.27.2Outdated
A practical functional library for JavaScript programmers.
dom-helpers 5.0.1 - 5.2.1
tiny modular DOM lib for ie9+
tiny-invariant 0.0.2 - 1.3.1Outdated
A tiny invariant function
@sentry/utils 5.21.0 - 6.5.1Outdated
Utilities for all Sentry JavaScript SDKs
+8
benvinegar
billyvg
mitsuhiko
immediate 2.4.3 - 2.6.1Outdated
A cross browser microtask library
cwmma
cwmma
@sentry/core 5.10.2 - 6.16.1Outdated
Base implementation for all Sentry JavaScript SDKs
+8
benvinegar
billyvg
mitsuhiko
redux 4.0.1Outdated
Predictable state container for JavaScript apps
react-fast-compare 2.0.4 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
stream-http 2.8.2 - 2.8.3Outdated
Streaming http in the browser
timers-browserify 2.0.9Outdated
timers module for browserify
d3-array 1.0.1 - 2.3.1Outdated
Array manipulation, ordering, searching, summarizing, etc.
character-entities-legacy 2.0.0Outdated
List of legacy HTML named character references that don’t need a trailing semicolon
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
reselect 4.1.0 - 4.1.7Outdated
Selectors for Redux.
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
@xmldom/xmldom 0.7.0 - 0.8.6Outdated
A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
history 4.0.0 - 4.6.1Outdated
Manage session history with JavaScript
raf 3.0.0 - 3.1.0Outdated
requestAnimationFrame polyfill for node and the browser
polished 2.1.1 - 4.2.2Outdated
A lightweight toolset for writing styles in Javascript.
d3-shape 1.0.2 - 3.2.0
Graphical primitives for visualization, such as lines and areas.
idb 5.0.0 - 7.1.1Outdated
A small wrapper that makes IndexedDB usable
jaffathecake
jaffathecake
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
fb
sophiebits
to-arraybuffer 1.0.1
Get an ArrayBuffer from a Buffer as fast as possible
d3-format 1.3.1 - 1.3.2Outdated
Format numbers for human consumption.
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
d3-timer 1.0.2 - 3.0.1
An efficient queue capable of managing thousands of concurrent animations.
redux-thunk 2.1.0 - 2.4.2Outdated
Thunk middleware for Redux.
lodash.throttle 4.1.1
The lodash method `_.throttle` exported as a module.
d3-ease 0.0.1 - 3.0.1
Easing functions for smooth animation.
react-popper 2.2.0 - 2.2.4Outdated
Official library to use Popper on React projects
popper.js 1.12.6 - 1.16.1
A kickass library to manage your poppers
intl-messageformat 2.1.0 - 2.2.0Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
framer-motion 3.8.0 - 8.5.0Outdated
A simple and powerful JavaScript animation library
@firebase/util 1.7.0 - 1.8.0Outdated
_NOTE: This is specifically tailored for Firebase JS SDK usage, if you are not a member of the Firebase team, please avoid using this package_
+1
chholland
firebase-ops
feiyang.chen
@firebase/component 0.5.8 - 0.6.0Outdated
Firebase Component Platform
+1
chholland
firebase-ops
feiyang.chen
@sentry/hub 4.3.3 - 6.19.4Outdated
Sentry hub which handles global state managment.
+8
benvinegar
billyvg
mitsuhiko
@firebase/logger 0.3.0 - 0.4.0Outdated
A logger package for use in the Firebase JS SDK
+1
chholland
firebase-ops
feiyang.chen
attr-accept 2.2.2
JavaScript implementation of the "accept" attribute for HTML5 <input type="file">
@sentry/minimal 4.0.0 - 6.19.7
Sentry minimal library that can be used in other packages
+8
benvinegar
billyvg
mitsuhiko
exenv 1.1.0 - 1.2.2
React's ExecutionEnvironment module extracted for use in other packages & components
shallow-equal 1.1.0 - 1.2.1Outdated
Typescript-compatible minimalistic shallow equality check for arrays/objects
reduce-css-calc 1.3.0Outdated
Reduce CSS calc() function to the maximum
string-convert 0.2.0 - 0.2.1
String convertions
akiran
akiran
json2mq 0.2.0
Generate media query string from JSON or javascript object
akiran
akiran
faker 2.0.1 - 2.1.5Outdated
Generate massive amounts of fake contextual data
marak
marak
react-side-effect 1.1.5Outdated
Create components whose prop changes map to a global side effect
gud 1.0.0
Create a 'gud nuff' (not cryptographically secure) globally unique id
react-helmet 5.2.0 - 5.2.1Outdated
A document head manager for React
@firebase/app 0.7.18 - 0.9.0Outdated
The primary entrypoint to the Firebase JS SDK
+1
chholland
firebase-ops
feiyang.chen
original 1.0.0 - 1.0.2
Generate the origin from an URL or check if two URL/Origins are the same
decimal.js-light 2.2.5 - 2.3.1Outdated
An arbitrary-precision Decimal type for JavaScript.
clipboard 2.0.3 - 2.0.4Outdated
Modern copy to clipboard. No Flash. Just 2kb
react-use 9.3.0 - 17.4.0Outdated
Collection of React Hooks
streamich
streamich
xstate 4.7.0 - 4.19.1Outdated
Finite State Machines and Statecharts for the Modern Web.
recharts 1.0.0 - 2.3.2Outdated
React charts
react-resize-detector 2.3.0Outdated
React resize detector
airbnb-prop-types 2.13.0 - 2.13.2Outdated
Custom React PropType validators that we use at Airbnb.
react-intl 2.1.4 - 2.9.0Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
recharts-scale 0.4.2 - 0.4.3Outdated
Scale of Cartesian Coordinates
intl-messageformat-parser 1.3.0 - 1.5.1Outdated
Parses ICU Message strings into an AST via JavaScript.
d3-collection 1.0.1 - 1.0.7
Handy data structures for elements keyed by string.
@material-ui/core 1.5.1 - 4.12.4
React components that implement Google's Material Design.
numeral 2.0.6
Format and manipulate numbers.
math-expression-evaluator 1.2.2 - 1.4.0Outdated
A flexible math expression evaluator
enquire.js 2.1.6
Awesome Media Queries in JavaScript
reduce-function-call 1.0.2 - 1.0.3
Reduce function calls in a string, using a callback
react-slick 0.23.0 - 0.23.2Outdated
React port of slick carousel
leaflet 1.3.2 - 1.9.1Outdated
JavaScript library for mobile-friendly interactive maps
consolidated-events 1.0.0 - 1.1.1Outdated
Manage multiple event handlers using few event listeners
document.contains 1.0.1Outdated
Polyfill/shim for `document.contains`
react-outside-click-handler 1.0.0 - 1.3.0
A React component for dealing with clicks outside its subtree
+2
brieb
airbnbeng
lencioni
react-with-direction 1.0.0 - 1.4.0
Components to provide and consume RTL or LTR direction in React
+4
brieb
airbnbeng
lencioni
html-to-react 1.3.1 - 1.4.1Outdated
A lightweight library that converts raw HTML to a React DOM structure.
react-with-styles 3.1.1Outdated
[![Build Status][travis-svg]][travis-url] [![dependency status][deps-svg]][deps-url] [![dev dependency status][dev-deps-svg]][dev-deps-url] [![License][license-image]][license-url] [![Downloads][downloads-image]][downloads-url]
react-moment-proptypes 1.6.0 - 1.8.1
React proptype for moment module
react-dates 20.2.1 - 20.2.3Outdated
A responsive and accessible date range picker component built with React
+4
lencioni
ljharb
ahuth
global-cache 1.2.0 - 1.2.1
Sometimes you have to do horrible things, like use the global object to share a singleton. Abstract that away, with this!
react-with-styles-interface-css 4.0.0 - 4.0.3Outdated
Interface for react-with-styles outputting CSS
react-paginate 6.3.0Outdated
A ReactJS component that creates a pagination.
@loadable/component 5.13.0 - 5.15.2Outdated
React code splitting made easy.
redux-form 0.3.0 - 6.4.3Outdated
A higher order component decorator for forms using Redux and React
react-autosuggest 9.4.1 - 9.4.3Outdated
WAI-ARIA compliant React autosuggest component
section-iterator 2.0.0
Simple iterator for flat and multi section lists
react-bootstrap-typeahead 4.0.0 - 5.1.4Outdated
React typeahead with Bootstrap styling
amplitude-js 4.7.0Outdated
Javascript library for Amplitude Analytics
intl-relativeformat 2.2.0Outdated
Formats JavaScript dates to relative time strings.
deepcopy 2.0.0 - 2.1.0
deep copy data
sasaplus1
sasaplus1
@atlaskit/icon 14.0.2 - 18.0.5Outdated
An icon is a visual representation of a command, device, directory, or common action.
atlaskit
atlaskit
react-autowhatever 8.0.0 - 10.2.0Outdated
Accessible rendering layer for Autosuggest and Autocomplete components
react-move 5.0.0 - 6.5.0
Beautiful, data-driven animations for React.
most 0.6.0 - 0.8.4Outdated
Monadic streams
gatsby-background-image 0.7.0 - 1.6.0
Lazy-loading React background-image component with optional support for the blur-up effect.
@rmwc/base 4.0.0 - 4.0.6Outdated
RMWC base module
jamesmfriedman
jamesmfriedman
woothee 0.3.0 - 1.11.1
User-Agent string parser (js implementation)
tagomoris
tagomoris
botframework-webchat-component 4.7.0 - 4.15.6Outdated
React component of botframework-webchat
+2
botframework
sgellock
cwhitten