news.yahoo.com 75 packages

Last scanned on Oct 27 at 07:04 PM
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
License
MIT
Footprint
7 KB
Vulnerabilities
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
react 0.13.0 - 0.13.3VulnerableOutdated
React is a JavaScript library for building user interfaces.
debug 3.0.0 - 3.1.0Outdated
Lightweight debugging utility for Node.js and the browser
ms 0.7.2 - 2.1.3
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
isarray 0.0.0 - 0.0.1Outdated
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
extend-shallow 2.0.0 - 2.0.1Outdated
Extend an object with the properties of additional objects. node.js/javascript util.
@babel/runtime 7.18.0 - 7.20.0Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
get-intrinsic 1.1.3Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
path-to-regexp 1.7.0 - 1.8.0Outdated
Express style path to RegExp utility
cookie 0.2.4 - 0.4.1Outdated
HTTP server cookie parsing and serialization
dougwilson
dougwilson
wrappy 0.0.0 - 1.0.2
Callback wrapping utility
isaacs
isaacs
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
es-abstract 1.18.7 - 1.20.4Outdated
ECMAScript spec abstract operations.
base64-js 1.3.1 - 1.5.1
Base64 encoding/decoding in pure JS
is-callable 1.2.7
Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.
has-tostringtag 1.0.0Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
which-typed-array 1.1.6 - 1.1.8Outdated
Which kind of Typed Array is this JavaScript value? Works cross-realm, without `instanceof`, and despite Symbol.toStringTag.
core-js 3.21.1Outdated
Standard library
is-typed-array 1.1.7 - 1.1.9Outdated
Is this value a JS Typed Array? This module works cross-realm/iframe, does not depend on `instanceof` or mutable properties, and despite ES6 Symbol.toStringTag.
available-typed-arrays 1.0.5Outdated
Returns an array of Typed Array names that are available in the current environment
util 0.12.0 - 0.12.5
Node.js's util module for all engines
eventemitter3 2.0.0 - 4.0.7Outdated
EventEmitter3 focuses on performance while maintaining a Node.js AND browser compatible interface.
for-each 0.3.3
A better forEach
ljharb
raynos
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
prop-types 15.5.0 - 15.8.1
Runtime type checking for React props and similar objects.
is-arguments 1.1.1
Is this an arguments object? It's a harder question than you think.
performance-now 0.1.3 - 2.1.0
Implements performance.now (based on process.hrtime).
meryn
meryn
is-generator-function 1.0.10
Determine if a function is a native generator function.
url 0.10.0 - 0.10.3Outdated
The core `url` packaged standalone for use with Browserify.
hoist-non-react-statics 1.2.0 - 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
querystring 0.2.0Outdated
Node's querystring module for all engines.
classnames 2.3.2Outdated
A simple utility for conditionally joining classNames together
query-string 5.0.1 - 5.1.1Outdated
Parse and stringify URL query strings
react-transition-group 1.0.0 - 1.2.1Outdated
A react component toolset for managing animations
graphql 16.0.0 - 16.6.0Outdated
A Query Language and Runtime which can target any service.
sha.js 2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
dom-helpers 3.4.0 - 5.2.1
tiny modular DOM lib for ie9+
react-router 0.5.3 - 0.9.3Outdated
Declarative routing for React
is-promise 2.1.0 - 4.0.0
Test whether an object looks like a promises-a+ promise
forbeslindesay
then-bot
lodash-es 4.17.21
Lodash exported as ES modules.
es6-promise 4.2.4 - 4.2.8
A lightweight library that provides tools for organizing asynchronous code
@storybook/router 6.5.0 - 6.5.13Outdated
Core Storybook Router
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
raf 1.0.0 - 3.4.1
requestAnimationFrame polyfill for node and the browser
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
copy-to-clipboard 3.3.2Outdated
Copy stuff into clipboard using JS with fallbacks
toggle-selection 1.0.5 - 1.0.6
Toggle current selected content in browser
intl-messageformat 2.1.0 - 2.2.0Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
is-function 1.0.2
is that thing a function? Use this module to find out
@angular/common 2.0.0 - 2.2.4Outdated
Angular - commonly needed directives and services
angular
google-wombot
formik 1.0.0 - 2.2.9Outdated
Build forms in React, without the tears
react-onclickoutside 6.2.0 - 6.12.2Outdated
An onClickOutside wrapper for React components
parse-headers 2.0.3 - 2.0.5
Parse http headers, works with browserify/xhr
create-react-class 15.7.0
Legacy API for creating React components.
react-intl 2.0.0 - 2.9.0Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
intl-messageformat-parser 1.3.0 - 1.5.1Outdated
Parses ICU Message strings into an AST via JavaScript.
react-bootstrap 0.11.1 - 0.21.0Outdated
Bootstrap 5 components built with React
mobx 4.13.1 - 6.0.5Outdated
Simple, scalable state management.
react-copy-to-clipboard 5.1.0
Copy-to-clipboard React component
inversify 2.0.0Outdated
A powerful and lightweight inversion of control container for JavaScript and Node.js apps powered by TypeScript.
react-spring 4.1.6 - 4.1.8Outdated
<p align="center"> <img src="https://i.imgur.com/QZownhg.png" width="240" /> </p>
@chakra-ui/utils 1.9.0 - 2.0.11Outdated
Common utilities and types for Chakra UI
segunadebayo
_codebender828
jsonp 0.2.0 - 0.2.1
A sane JSONP implementation.
tootallnate
rauchg
feross
intl-format-cache 2.2.2 - 4.1.16Outdated
A memoizer factory for Intl format constructors.
chain-function 1.0.0 - 1.0.1
chain a bunch of functions together into a single call
monastic.panic
monastic.panic
react-autosuggest 10.0.1 - 10.1.0
WAI-ARIA compliant React autosuggest component
amplitude-js 5.2.0Outdated
Javascript library for Amplitude Analytics
intl-relativeformat 2.2.0Outdated
Formats JavaScript dates to relative time strings.
subscribe-ui-event 1.0.5 - 1.1.2Outdated
A single, throttle built-in solution to subscribe to browser UI Events.
react-dom-core 0.0.2 - 0.0.4Outdated
Copy of react-dom 15
@iabtcf/core 1.5.3Outdated
Ensures consistent encoding and decoding of TC Signals for the iab. Transparency and Consent Framework (TCF).
@iabtcf/cmpapi 1.1.0 - 1.5.3Outdated
Ensures other in-page digital marketing technologies have access to CMP transparency and consent information for the iab. Transparency and Consent Framework (TCF).