kununu.com 80 packages

Last scanned on Oct 27 at 06:42 PM
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
License
MIT
Footprint
3 KB
Vulnerabilities
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
postcss 8.4.17VulnerableOutdated
Tool for transforming styles with JS plugins
sanitize-html 2.5.2 - 2.7.0VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
next 12.0.8 - 12.1.6VulnerableOutdated
The React Framework
rauchg
timneutkens
vercel-release-bot
ms 2.1.2 - 2.1.3
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
readable-stream 3.6.0Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
escape-string-regexp 4.0.0 - 5.0.0
Escape RegExp special characters
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
uuid 8.3.0 - 9.0.0Outdated
RFC4122 (v1, v4, and v5) UUIDs
isarray 0.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 18.2.0
Brand checking of React Elements.
inherits 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
is-stream 1.0.0 - 3.0.0Outdated
Check if something is a Node.js stream
qs 6.7.0 - 6.9.6Outdated
A querystring parser that supports nesting and arrays, with a depth limit
entities 2.2.0Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.13.6 - 7.13.7Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
path-to-regexp 1.7.0 - 1.8.0Outdated
Express style path to RegExp utility
cookie 0.2.4 - 0.4.1Outdated
HTTP server cookie parsing and serialization
dougwilson
dougwilson
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
is-plain-object 4.1.0 - 5.0.0
Returns true if an object was created by the `Object` constructor, or Object.create(null).
domutils 2.8.0Outdated
Utilities for working with htmlparser2's dom
dom-serializer 1.0.0 - 1.4.1Outdated
render domhandler DOM nodes to a string
domhandler 4.2.2 - 4.3.1Outdated
Handler for htmlparser2 that turns pages into a dom
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
domelementtype 2.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
core-js 3.19.0 - 3.22.3Outdated
Standard library
clone 2.1.0 - 2.1.2
deep cloning of objects and arrays
pvorb
pvorb
htmlparser2 6.1.0Outdated
Fast & forgiving HTML/XML parser
scheduler 0.15.0 - 0.23.0
Cooperative scheduler for the browser environment.
prop-types 15.7.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 17.0.0 - 18.2.0
React is a JavaScript library for building user interfaces.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
querystring 0.2.1
Node's querystring module for all engines.
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
fast-safe-stringify 2.0.4 - 2.0.6Outdated
Safely and quickly serialize JavaScript objects
stack-trace 0.0.10Outdated
Get v8 stack traces as an array of CallSite objects.
+3
felixge
sebastianhoitz
tim-smart
@popperjs/core 2.8.5 - 2.11.6Outdated
Tooltip and Popover Positioning Engine
winston 3.2.1Outdated
A logger for just about everything.
react-router 5.0.0 - 5.0.1Outdated
Declarative routing for React
lodash-es 4.17.21
Lodash exported as ES modules.
redux 4.1.0 - 4.2.0Outdated
Predictable state container for JavaScript apps
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
winston-transport 4.4.0 - 4.5.0Outdated
Base stream implementations for winston@3 and up.
logform 2.4.0 - 2.4.2Outdated
An mutable object-based log format designed for chaining & objectMode streams.
fecha 4.0.0 - 4.2.3
Date formatting and parsing
triple-beam 1.2.0 - 1.3.0Outdated
Definitions of levels for logging purposes & shareable Symbol constants.
enabled 1.0.2Outdated
Check if a certain debug flag is enabled.
one-time 0.0.4Outdated
Run the supplied function exactly one time (once)
url-join 4.0.0Outdated
Join urls and normalize as in path.join.
jwt-decode 2.2.0Outdated
Decode JWT tokens, mostly useful for browser applications.
resize-observer-polyfill 1.5.0 - 1.5.1
A polyfill for the Resize Observer API
camelize 0.1.2 - 1.0.1
recursively transform key strings to camel-case
libphonenumber-js 1.9.1 - 1.10.14Outdated
A simpler (and smaller) rewrite of Google Android's libphonenumber library in javascript
react-popper 2.2.5 - 2.3.0
Official library to use Popper on React projects
intl-messageformat 2.1.0 - 2.2.0Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
xss 1.0.13 - 1.0.14Outdated
Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
cssfilter 0.0.10
Sanitize untrusted CSS with a configuration specified by a Whitelist. 根据白名单过滤CSS
string-convert 0.2.0 - 0.2.1
String convertions
akiran
akiran
json2mq 0.2.0
Generate media query string from JSON or javascript object
akiran
akiran
gud 1.0.0
Create a 'gud nuff' (not cryptographically secure) globally unique id
qrcode 0.8.0 - 0.8.2Outdated
QRCode / 2d Barcode api with both server side and client side support using canvas
parse-srcset 1.0.0 - 1.0.2
A spec-conformant JavaScript parser for the HTML5 srcset attribute
albell
albell
http-status-codes 1.0.4 - 1.4.0Outdated
Constants enumerating the HTTP status codes. Based on the Java Apache HttpStatus API.
universal-cookie 4.0.1 - 4.0.4Outdated
Universal cookies for JavaScript
react-intl 2.6.0 - 2.9.0Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
intl-messageformat-parser 1.3.0 - 1.5.1Outdated
Parses ICU Message strings into an AST via JavaScript.
enquire.js 2.1.6
Awesome Media Queries in JavaScript
react-slick 0.23.0 - 0.23.2Outdated
React port of slick carousel
@reach/utils 0.10.4 - 0.11.2Outdated
Internal, shared utilities for Reach UI.
+1
ryanflorence
mjackson
chancestrickland
react-player 1.12.0 - 1.15.2Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
body-scroll-lock 2.7.0 - 3.1.5Outdated
Enables body scroll locking (for iOS Mobile and Tablet, Android, desktop Safari/Chrome/Firefox) without breaking scrolling of a target element (eg. modal/lightbox/flyouts/nav-menus)
react-content-loader 5.0.0 - 6.2.0Outdated
SVG-Powered component to easily create placeholder loadings (like Facebook cards loading)
react-from-dom 0.6.0 - 0.6.2Outdated
Convert HTML/XML source code or DOM nodes to React elements
react-lazyload 2.4.0 - 2.5.0Outdated
Lazyload your components, images or anything where performance matters.
intl-relativeformat 2.2.0Outdated
Formats JavaScript dates to relative time strings.
react-facebook 4.1.1 - 5.0.3Outdated
Facebook components like a Login button, Like, Share, Comments, Embedded Post/Video, Messenger Chat and others
most-subject 6.0.0
Subjects for @most/core
+1
brandonpayton
ntilwalli
axefrog
@team-griffin/react-heading-section 2.0.0 - 2.2.0Outdated
```sh npm i --save @team-griffin/react-heading-section
+1
christierobson
jackmellis
jshthornton