nextdoor.com 134 packages

Last scanned on Oct 27 at 06:16 PM
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
License
MIT
Footprint
22 KB
Vulnerabilities
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
axios 0.18.1VulnerableOutdated
Promise based HTTP client for the browser and node.js
ms 0.7.2 - 1.0.0VulnerableOutdated
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
es5-ext 0.10.1 - 0.10.62VulnerableOutdated
ECMAScript extensions and shims
debug 2.3.1 - 3.1.0Outdated
Lightweight debugging utility for Node.js and the browser
tslib 1.6.0 - 2.4.0Outdated
Runtime library for TypeScript helper functions
isarray 0.0.0 - 0.0.1Outdated
Array#isArray for older browsers
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
qs 6.5.3Outdated
A querystring parser that supports nesting and arrays, with a depth limit
bytes 2.0.2Outdated
Utility to parse a string bytes to bytes and vice-versa
@babel/runtime 7.18.2 - 7.20.0Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
get-intrinsic 1.1.3Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
path-to-regexp 1.7.0 - 1.8.0Outdated
Express style path to RegExp utility
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
has-property-descriptors 1.0.0Outdated
Does the environment have full property descriptor support? Handles IE 8's broken defineProperty/gOPD.
define-properties 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
has-tostringtag 1.0.0Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
is-buffer 2.0.0 - 2.0.5
Determine if an object is a Buffer
object-keys 1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
regexp.prototype.flags 1.4.2 - 1.4.3Outdated
ES6 spec-compliant RegExp.prototype.flags shim.
core-js 2.6.12Outdated
Standard library
is-regex 1.1.4
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
is-date-object 1.0.5
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
functions-have-names 1.1.1 - 1.2.3
Does this JS environment support the `name` property on functions?
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
scheduler 0.15.0 - 0.23.0
Cooperative scheduler for the browser environment.
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
is-arguments 1.1.1
Is this an arguments object? It's a harder question than you think.
react 17.0.0 - 17.0.2Outdated
React is a JavaScript library for building user interfaces.
deep-equal 1.1.0 - 1.1.1Outdated
node's assert.deepEqual algorithm
object-is 1.1.0 - 1.1.5Outdated
ES2015-compliant shim for Object.is - differentiates between -0 and +0
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
querystring 0.2.1
Node's querystring module for all engines.
classnames 2.3.2Outdated
A simple utility for conditionally joining classNames together
stylis 4.0.0 - 4.0.5Outdated
A Light–weight CSS Preprocessor
andarist
thysultan
query-string 5.0.1 - 5.1.1Outdated
Parse and stringify URL query strings
react-transition-group 1.0.0 - 2.5.2Outdated
A react component toolset for managing animations
graphql 15.5.0 - 15.8.0Outdated
A Query Language and Runtime which can target any service.
dom-helpers 3.4.0Outdated
tiny modular DOM lib for ie9+
underscore 1.11.0 - 1.13.6
JavaScript's functional programming helper library.
@emotion/serialize 0.11.12 - 0.11.16Outdated
serialization utils for emotion
+1
emmatown
tkh44
emotion-release-bot
@emotion/utils 0.0.4 - 1.2.0Outdated
internal utils for emotion
+1
emmatown
tkh44
emotion-release-bot
tiny-invariant 0.0.2 - 1.3.1Outdated
A tiny invariant function
@sentry/utils 6.19.5 - 6.19.7Outdated
Utilities for all Sentry JavaScript SDKs
+8
benvinegar
billyvg
mitsuhiko
memoize-one 5.1.0 - 5.1.1Outdated
A memoization library which only remembers the latest invocation
@emotion/sheet 0.9.1 - 0.9.4Outdated
emotion's stylesheet
+1
emmatown
tkh44
emotion-release-bot
react-router 1.0.1 - 1.0.3Outdated
Declarative routing for React
@sentry/core 6.19.7Outdated
Base implementation for all Sentry JavaScript SDKs
+8
benvinegar
billyvg
mitsuhiko
react-router-dom 5.1.0 - 5.3.4Outdated
Declarative routing for React web applications
lodash-es 4.17.21
Lodash exported as ES modules.
redux 4.1.0 - 4.2.0Outdated
Predictable state container for JavaScript apps
tailwindcss 1.4.2 - 1.7.1Outdated
A utility-first CSS framework for rapidly building custom user interfaces.
malfaitrobin
adamwathan
reinink
babel-runtime 6.18.0 - 6.26.0
babel selfContained runtime
hzoo
loganfsmyth
existentialism
socket.io-parser 2.1.0 - 2.3.1Outdated
socket.io protocol parser
rauchg
darrachequesne
linkify-it 2.2.0Outdated
Links recognition library with FULL unicode support
history 4.0.0 - 4.10.1Outdated
Manage session history with JavaScript
engine.io-parser 0.1.0 - 2.2.1Outdated
Parser for the client for the realtime Engine
rauchg
darrachequesne
uc.micro 1.0.6Outdated
Micro subset of unicode data files for markdown-it projects.
vitaly
vitaly
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
fb
sophiebits
@sentry/browser 6.19.0 - 6.19.7Outdated
Official Sentry SDK for browsers
+8
benvinegar
billyvg
mitsuhiko
libphonenumber-js 1.10.13Outdated
A simpler (and smaller) rewrite of Google Android's libphonenumber library in javascript
react-select 1.2.0 - 1.3.0Outdated
A Select control built with and for ReactJS
zen-observable-ts 1.1.0 - 1.2.3
Thin wrapper around zen-observable and @types/zen-observable, to support ESM exports as well as CommonJS exports
jbaxleyiii
apollo-bot
@wry/trie 0.2.1 - 0.3.2Outdated
https://en.wikipedia.org/wiki/Trie
socket.io-client 1.5.0 - 1.7.4Outdated
Realtime application framework client
base64-arraybuffer 0.1.5 - 1.0.2
Encode/decode base64 data into ArrayBuffers
niklasvh
niklasvh
engine.io-client 3.1.3 - 3.2.1Outdated
Client for the realtime Engine
rauchg
darrachequesne
@wry/equality 0.5.3Outdated
Structural equality checking for JavaScript values
benjamn
benjamn
framer-motion 4.1.12 - 4.1.17Outdated
A simple and powerful JavaScript animation library
tabbable 3.1.1 - 3.1.2Outdated
Returns an array of all tabbable DOM nodes within a containing node.
davidtheclark
stefcameron
@wry/context 0.4.0 - 0.6.1Outdated
Manage contextual information needed by (a)synchronous tasks without explicitly passing objects around
benjamn
benjamn
optimism 0.16.1Outdated
Composable reactive caching with efficient invalidation.
@sentry/hub 7.0.0 - 7.14.2Outdated
Sentry hub which handles global state managment.
+8
benvinegar
billyvg
mitsuhiko
@apollo/client 3.4.11 - 3.4.13Outdated
A fully-featured caching GraphQL client.
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
react-textarea-autosize 8.0.0 - 8.3.4Outdated
textarea component for React which grows with content
@sentry/tracing 6.19.5 - 6.19.7Outdated
Sentry Performance Monitoring Package
+8
benvinegar
billyvg
mitsuhiko
uncontrollable 3.0.0 - 7.2.1Outdated
Wrap a controlled react component, to allow specific prop/handler pairs to be uncontrolled
@emotion/core 0.13.0 - 10.3.1Outdated
+1
emmatown
tkh44
emotion-release-bot
framesync 4.1.0 - 6.1.2
A frame-synced render loop for JavaScript
popmotion
popmotion
react-input-autosize 2.2.2Outdated
Auto-resizing Input Component for React
parseuri 0.0.4 - 0.0.5Outdated
Method that parses a URI and returns an array of its components
gal
gal
mini-create-react-context 0.3.3 - 0.4.1
Smaller Polyfill for the proposed React context API
create-react-class 15.7.0
Legacy API for creating React components.
lit-element 3.0.0Outdated
A simple base class for creating fast, lightweight web components
+11
aomarks
emarquez
sorvell
react-use 8.1.2 - 13.24.1Outdated
Collection of React Hooks
streamich
streamich
yeast 0.1.2
Tiny but linear growing unique id generator
recharts 1.0.0 - 1.8.5Outdated
React charts
blob 0.0.1 - 0.0.4Outdated
Abstracts out Blob and uses BlobBuilder in cases where it is supported with any vendor prefix.
amitport
rase-
xstate 4.7.0 - 4.19.1Outdated
Finite State Machines and Statecharts for the Modern Web.
focus-trap 4.0.0 - 4.0.2Outdated
Trap focus within a DOM node.
rc-motion 1.0.0 - 2.6.2Outdated
React lifecycle controlled motion library
after 0.8.1 - 0.8.2
after - tiny flow control
component-bind 1.0.0
function binding utility
arraybuffer.slice 0.0.6 - 0.0.7
Exports a function for slicing ArrayBuffers (no polyfilling)
rase-
rase-
component-inherit 0.0.3
Prototype inheritance utility
coreh
coreh
to-array 0.1.3 - 0.1.4
Turn an array like into an array
raynos
raynos
popmotion 9.0.0 - 11.0.5
The animator's toolbox
style-value-types 4.1.0 - 4.1.5Outdated
Parsers, transformers and tests for special value types, eg: %, hex codes etc.
react-overlays 0.5.0 - 5.2.1
Utilities for creating robust overlay components
mobx 2.6.0 - 6.6.2Outdated
Simple, scalable state management.
react-bootstrap 0.32.0 - 0.32.1Outdated
Bootstrap 5 components built with React
keycode 2.1.2 - 2.2.1
Convert between keyboard keycodes and keynames and vice versa.
react-player 1.12.0 - 1.15.3Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
immutability-helper 2.7.1 - 2.9.1Outdated
mutate a copy of data without changing the original source
@chakra-ui/theme 2.1.0 - 2.1.3Outdated
The default theme for chakra components
focus-trap-react 5.0.0 - 6.0.0Outdated
A React component that traps focus.
@chakra-ui/hooks 2.0.0 - 2.1.0Outdated
React hooks for Chakra components
scriptjs 2.5.6 - 2.5.9
Asyncronous JavaScript loader and dependency manager
chain-function 1.0.0 - 1.0.1
chain a bunch of functions together into a single call
monastic.panic
monastic.panic
react-ga 1.4.1 - 2.7.0Outdated
React Google Analytics Module
amplitude-js 5.2.0Outdated
Javascript library for Amplitude Analytics
react-prop-types 0.4.0
Additional PropTypes for React
@fingerprintjs/fingerprintjs 3.3.1 - 3.3.6Outdated
Browser fingerprinting library with the highest accuracy and stability
react-visibility-sensor 3.10.1 - 3.11.1Outdated
Sensor component for React that notifies you when it goes in or out of the window viewport.
store 2.0.12
A localStorage wrapper for all browsers without using cookies or flash. Uses localStorage, globalStorage, and userData behavior under the hood
marcuswestin
marcuswestin
analytics-utils 0.4.2 - 1.0.10Outdated
Analytics utility functions used by 'analytics' module
react-multi-carousel 1.0.0 - 1.0.18Outdated
Production-ready, lightweight fully customizable React carousel component that rocks supports multiple items and SSR(Server-side rendering) with typescript.
crypto-hash 0.1.0 - 2.0.1Outdated
Tiny hashing module that uses the native crypto API in Node.js and the browser
reakit-utils 0.9.0Outdated
Reakit utils
reakit-system 0.8.0 - 0.9.0Outdated
Reakit System utils
reakit 1.0.0 - 1.0.2Outdated
Toolkit for building accessible rich web apps with React
@apollo/react-components 3.0.0 - 3.1.5Outdated
React Apollo Query, Mutation and Subscription components.
no-scroll 2.1.0 - 2.1.1
Disable the document's scrolling
@theme-ui/core 0.3.0 - 0.3.5Outdated
[![Minified Size on Bundlephobia](https://badgen.net/bundlephobia/minzip/@theme-ui/core)](https://bundlephobia.com/package/@theme-ui/core)
+1
jxnblk
johno
hasparus
@tannin/plural-forms 1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
aduth
@theme-ui/theme-provider 0.3.0 - 0.8.4Outdated
**Note:** This package is a hack to fix export order produced by microbundle. Use the main `theme-ui` package or `@theme-ui/core` instead.
+1
jxnblk
johno
hasparus
most 0.6.0 - 0.9.1Outdated
Monadic streams
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
airnan
airnan
botframework-webchat-component 4.4.1 - 4.11.0Outdated
React component of botframework-webchat
+2
botframework
sgellock
cwhitten
@team-griffin/react-heading-section 1.0.0 - 3.1.1
```sh npm i --save @team-griffin/react-heading-section
+1
christierobson
jackmellis
jshthornton