hilton.com 115 packages

Last scanned on Oct 27 at 07:01 PM
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
License
MIT
Footprint
2 KB
Vulnerabilities
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
sanitize-html 2.4.0 - 2.5.0VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
lodash.set 4.3.1 - 4.3.2Vulnerable
The lodash method `_.set` exported as a module.
postcss 8.4.8VulnerableOutdated
Tool for transforming styles with JS plugins
next 9.4.2 - 10.2.3VulnerableOutdated
The React Framework
rauchg
timneutkens
vercel-release-bot
tslib 1.2.0 - 2.4.0Outdated
Runtime library for TypeScript helper functions
readable-stream 3.6.0Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
escape-string-regexp 4.0.0 - 5.0.0
Escape RegExp special characters
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
uuid 8.3.0 - 8.3.2Outdated
RFC4122 (v1, v4, and v5) UUIDs
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
inherits 2.0.3 - 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
entities 2.2.0Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.18.0Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
get-intrinsic 1.1.0 - 1.1.1Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
axios 0.24.0Outdated
Promise based HTTP client for the browser and node.js
cookie 0.4.1 - 0.4.2Outdated
HTTP server cookie parsing and serialization
dougwilson
dougwilson
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
is-plain-object 4.1.0 - 5.0.0
Returns true if an object was created by the `Object` constructor, or Object.create(null).
domutils 2.8.0Outdated
Utilities for working with htmlparser2's dom
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
fast-json-stable-stringify 2.0.0 - 2.1.0
deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify
define-properties 1.1.3 - 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
dom-serializer 1.0.0 - 1.4.1Outdated
render domhandler DOM nodes to a string
domhandler 4.2.2 - 4.3.1Outdated
Handler for htmlparser2 that turns pages into a dom
has-tostringtag 1.0.0Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
object-keys 1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
regexp.prototype.flags 1.4.1Outdated
ES6 spec-compliant RegExp.prototype.flags shim.
domelementtype 2.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
is-regex 1.1.4
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
is-date-object 1.0.5
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
util 0.10.0 - 0.12.5
Node.js's util module for all engines
content-type 1.0.4Outdated
Create and parse HTTP Content-Type header
htmlparser2 6.1.0Outdated
Fast & forgiving HTML/XML parser
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
scheduler 0.15.0 - 0.23.0
Cooperative scheduler for the browser environment.
emittery 0.7.0 - 0.8.1Outdated
Simple and modern async event emitter
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
is-arguments 1.1.1
Is this an arguments object? It's a harder question than you think.
react 17.0.0 - 17.0.2Outdated
React is a JavaScript library for building user interfaces.
deep-equal 1.1.0 - 1.1.1Outdated
node's assert.deepEqual algorithm
date-fns 2.19.0 - 2.23.0Outdated
Modern JavaScript date utility library
kossnocorp
kossnocorp
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
object-is 1.1.0 - 1.1.5Outdated
ES2015-compliant shim for Object.is - differentiates between -0 and +0
hoist-non-react-statics 1.2.0 - 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
path-browserify 0.0.0 - 0.0.1Outdated
the path module from node core for browsers
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
query-string 5.0.1 - 5.1.1Outdated
Parse and stringify URL query strings
sha.js 2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
graphql 14.4.2 - 14.7.0Outdated
A Query Language and Runtime which can target any service.
klona 2.0.5Outdated
A tiny (240B to 501B) and fast utility to "deep clone" Objects, Arrays, Dates, RegExps, and more!
asn1.js 5.2.0 - 5.4.1
ASN.1 encoder and decoder
hash-base 3.0.4 - 3.1.0
abstract base class for hash-streams
elliptic 6.5.4Outdated
EC cryptography
hash.js 1.1.2 - 1.1.7
Various hash functions that could be run by both browser and node
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
lodash-es 4.17.21
Lodash exported as ES modules.
des.js 1.0.1Outdated
DES implementation
md5.js 1.1.0 - 1.3.5
node style md5 on pure JavaScript
cipher-base 1.0.4
abstract base class for crypto-streams
pbkdf2 3.1.0 - 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
parse-asn1 5.1.6Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
browserify-sign 2.4.0 - 2.8.0Outdated
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
browserify-aes 0.4.0 - 0.8.1Outdated
aes, for browserify
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 4.1.0
RSA for browserify
+2
dcousens
ljharb
cwmma
create-ecdh 3.0.0 - 4.0.4
createECDH but browserifiable
diffie-hellman 1.1.2Outdated
pure js diffie-hellman
browserify-des 1.0.2
browserify-des ===
dcousens
ljharb
cwmma
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
miller-rabin 1.1.0 - 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.0 - 1.0.4
random fill from browserify stand alone
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
void-elements 3.1.0
Array of "void elements" defined by the HTML specification.
@xmldom/xmldom 0.7.0 - 0.8.3Outdated
A pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module.
graphql-tag 2.9.1 - 2.12.6
A JavaScript template literal tag that parses GraphQL queries
jnwng
abernix
apollo-bot
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
i18next 21.5.0 - 22.0.3Outdated
i18next internationalization framework
react-hook-form 7.0.0 - 7.28.1Outdated
Performant, flexible and extensible forms library for React Hooks
zen-observable 0.8.15Outdated
An Implementation of ES Observables
zenparsing
zenparsing
@wry/equality 0.1.8 - 0.1.11Outdated
Structural equality checking for JavaScript values
benjamn
benjamn
tabbable 4.0.0Outdated
Returns an array of all tabbable DOM nodes within a containing node.
davidtheclark
stefcameron
react-i18next 11.18.0 - 12.0.0Outdated
Internationalization for react done right. Using the i18next i18n ecosystem.
@apollo/client 3.5.6 - 3.7.1Outdated
A fully-featured caching GraphQL client.
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
@hookform/resolvers 1.1.0Outdated
React Hook Form validation resolvers: Yup, Joi, Superstruct, Zod, Vest, Class Validator, io-ts, Nope, computed-types, TypeBox, arktype and Typanion
@turf/helpers 5.1.0 - 6.5.0
turf helpers module
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
faker 2.0.1 - 2.1.5Outdated
Generate massive amounts of fake contextual data
marak
marak
react-dnd 9.1.0 - 10.0.2Outdated
Drag and Drop for React
+2
jordangens
gaearon
darthtrevino
parse-srcset 1.0.0 - 1.0.2
A spec-conformant JavaScript parser for the HTML5 srcset attribute
albell
albell
@turf/invariant 5.0.0 - 6.5.0
turf invariant module
universal-cookie 4.0.1 - 4.0.4Outdated
Universal cookies for JavaScript
react-query 3.39.2Outdated
Hooks for managing, caching and syncing asynchronous and remote data in React
tannerlinsley
tkdodo
apollo-link 1.2.9 - 1.2.14
Flexible, lightweight transport layer for GraphQL
jbaxleyiii
peggyrayzis
apollo-bot
i18next-http-backend 1.4.4 - 2.0.0Outdated
i18next-http-backend is a backend layer for i18next using in Node.js, in the browser and for Deno.
@reach/utils 0.16.0 - 0.17.0Outdated
Internal, shared utilities for Reach UI.
+1
ryanflorence
mjackson
chancestrickland
react-player 1.12.0 - 1.15.3Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
use-subscription 1.3.0 - 1.5.1Outdated
Reusable hooks
+1
gnoff
fb
sophiebits
inversify 5.1.1Outdated
A powerful and lightweight inversion of control container for JavaScript and Node.js apps powered by TypeScript.
change-emitter 0.1.2 - 0.1.6
Listen for changes. Like an event emitter that only emits a single event type. Really tiny.
apollo-link-error 1.1.6 - 1.1.13
Error Apollo Link for GraphQL Network Stack
apollo-bot
apollo-bot
credit-card-type 9.1.0Outdated
A library for determining credit card type
braintree
braintree
@reach/observe-rect 1.1.0 - 1.2.0
Observe the Rect of a DOM element.
+1
blainekasten
chancestrickland
mjackson
@apollo/react-common 3.0.0 - 3.1.4
React Apollo common utilities.
deepcopy 2.0.0 - 2.1.0
deep copy data
sasaplus1
sasaplus1
feathers-commons 0.8.5 - 0.8.7
Shared Feathers utility functions
react-amphtml 3.1.0 - 4.0.2
Use amphtml components inside your React apps easily!
dfrankland
dfrankland