opencollective.com 187 packages

Last scanned on Oct 27 at 07:08 PM
jsonwebtoken 8.5.0 - 8.5.1VulnerableOutdated
JSON Web Token implementation (symmetric and asymmetric)
License
MIT
Footprint
8 KB
Vulnerabilities
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Affected versions >=0 <9.0.0
jsonwebtoken unrestricted key type could lead to legacy keys usage
Affected versions >=0 <9.0.0
jsonwebtoken has insecure input validation in jwt.verify function
Affected versions >=0 <9.0.0
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
Affected versions >=0 <9.0.0
Matched Modules
Version distribution in production
66
8.5.0
66
8.5.1
4
8.2.1
4
8.2.2
4
8.4.0
3
8.2.0
postcss 8.4.14VulnerableOutdated
Tool for transforming styles with JS plugins
graphql 16.5.0VulnerableOutdated
A Query Language and Runtime which can target any service.
sanitize-html 2.7.2VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
next 12.3.1VulnerableOutdated
The React Framework
rauchg
timneutkens
vercel-release-bot
semver 5.7.0 - 5.7.1Outdated
The semantic version parser used by npm.
+2
npm-cli-ops
saquibkhan
fritzy
tslib 2.4.0Outdated
Runtime library for TypeScript helper functions
ms 2.1.2Outdated
Tiny millisecond conversion utility
+5
gdborton
matheuss
rauchg
escape-string-regexp 4.0.0Outdated
Escape RegExp special characters
safe-buffer 5.2.1
Safer Node.js Buffer API
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
uuid 9.0.0Outdated
RFC4122 (v1, v4, and v5) UUIDs
react-is 17.0.2Outdated
Brand checking of React Elements.
inherits 1.0.1 - 2.0.3Outdated
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 5.7.1Outdated
Node.js Buffer API, for the browser
picocolors 0.2.0 - 1.0.0
The tiniest and the fastest library for terminal output formatting with ANSI colors
entities 2.2.0Outdated
Encode & decode XML and HTML entities with ease & speed
node-fetch 2.6.1 - 2.6.7Outdated
A light-weight module that brings Fetch API to node.js
@babel/runtime 7.18.2 - 7.18.3Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
lodash 4.17.21
Lodash modular utilities.
path-to-regexp 6.1.0 - 6.2.0Outdated
Express style path to RegExp utility
caniuse-lite 0.2.0 - 1.0.30001426Outdated
A smaller version of caniuse-db, with only the essentials!
ieee754 1.2.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
is-plain-object 5.0.0
Returns true if an object was created by the `Object` constructor, or Object.create(null).
domutils 2.8.0Outdated
Utilities for working with htmlparser2's dom
base64-js 1.5.1
Base64 encoding/decoding in pure JS
fast-json-stable-stringify 2.0.0 - 2.1.0
deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify
dom-serializer 1.3.2 - 1.4.1Outdated
render domhandler DOM nodes to a string
nanoid 3.3.0 - 3.3.4Outdated
A tiny (116 bytes), secure URL-friendly unique string ID generator
domhandler 4.3.1Outdated
Handler for htmlparser2 that turns pages into a dom
events 3.3.0
Node's event emitter for all engines.
deepmerge 2.1.0 - 3.0.0Outdated
A library for deep (recursive) merging of Javascript objects
domelementtype 2.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
util 0.11.1Outdated
Node.js's util module for all engines
htmlparser2 6.1.0Outdated
Fast & forgiving HTML/XML parser
scheduler 0.20.2Outdated
Cooperative scheduler for the browser environment.
globalthis 1.0.1 - 1.0.3
ECMAScript spec-compliant polyfill/shim for `globalThis`
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 17.0.2Outdated
React is a JavaScript library for building user interfaces.
process 0.11.10
process information for node.js and browsers
jws 3.2.1 - 4.0.0
Implementation of JSON Web Signatures
jwa 1.4.1Outdated
JWA implementation (supports all JWS algorithms)
react-dom 17.0.2Outdated
React package for working with the DOM.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
performance-now 2.0.0 - 2.1.0
Implements performance.now (based on process.hrtime).
meryn
meryn
lodash.isplainobject 4.0.6
The lodash method `_.isPlainObject` exported as a module.
dayjs 1.11.2Outdated
2KB immutable date time library alternative to Moment.js with the same modern API
clsx 1.1.1Outdated
A tiny (239B) utility for constructing className strings conditionally.
@emotion/memoize 0.6.6 - 0.7.4Outdated
emotion's memoize utility
+1
emmatown
tkh44
emotion-release-bot
hoist-non-react-statics 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
querystring 0.2.0Outdated
Node's querystring module for all engines.
cross-fetch 3.1.5Outdated
Universal WHATWG Fetch API for Node, Browsers and React Native
ecdsa-sig-formatter 1.0.10 - 1.0.11
Translate ECDSA signatures between ASN.1/DER and JOSE-style concatenation
d2l-travis-deploy
d2l-travis-deploy
buffer-equal-constant-time 1.0.0 - 1.0.1
Constant-time comparison of Buffers
@emotion/unitless 0.7.2 - 0.7.5Outdated
An object of css properties that don't accept values with units
+1
emmatown
tkh44
emotion-release-bot
lodash.once 4.1.1
The lodash method `_.once` exported as a module.
classnames 2.3.2Outdated
A simple utility for conditionally joining classNames together
lodash.isstring 4.0.1
The lodash method `_.isString` exported as a module.
stylis 4.0.13Outdated
A Light–weight CSS Preprocessor
andarist
thysultan
@emotion/is-prop-valid 1.1.2Outdated
A function to check whether a prop is valid for HTML and SVG elements
+1
emmatown
tkh44
emotion-release-bot
react-transition-group 4.4.0 - 4.4.2Outdated
A react component toolset for managing animations
@emotion/hash 0.8.0Outdated
A MurmurHash2 implementation
+1
emmatown
tkh44
emotion-release-bot
lodash.isboolean 3.0.3
The lodash method `_.isBoolean` exported as a module.
@emotion/serialize 1.0.3Outdated
serialization utils for emotion
+1
emmatown
tkh44
emotion-release-bot
@popperjs/core 2.11.3 - 2.11.5Outdated
Tooltip and Popover Positioning Engine
@emotion/utils 1.1.0Outdated
internal utils for emotion
+1
emmatown
tkh44
emotion-release-bot
validator 13.7.0Outdated
String validation and sanitization
lodash.includes 4.3.0
The lodash method `_.includes` exported as a module.
@floating-ui/dom 1.0.2Outdated
Floating UI for the web
memoize-one 6.0.0
A memoization library which only remembers the latest invocation
lodash.isinteger 4.0.4
The lodash method `_.isInteger` exported as a module.
@sentry/utils 7.16.0Outdated
Utilities for all Sentry JavaScript SDKs
+8
benvinegar
billyvg
mitsuhiko
lodash.isnumber 3.0.3
The lodash method `_.isNumber` exported as a module.
@floating-ui/core 1.0.0 - 1.0.1Outdated
Positioning library for floating elements: tooltips, popovers, dropdowns, and more
@emotion/cache 11.7.1Outdated
emotion's cache
+1
emmatown
tkh44
emotion-release-bot
@emotion/sheet 1.1.0Outdated
emotion's stylesheet
+1
emmatown
tkh44
emotion-release-bot
@sentry/core 0.1.0 - 0.3.0Outdated
Base implementation for all Sentry JavaScript SDKs
+8
benvinegar
billyvg
mitsuhiko
@storybook/theming 6.5.0 - 6.5.13Outdated
Core Storybook Components
lodash-es 4.17.20 - 4.17.21
Lodash exported as ES modules.
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
warning 4.0.3
A mirror of Facebook's Warning
crypto-browserify 1.0.9 - 2.0.0Outdated
implementation of crypto for the browser
+2
dcousens
ljharb
cwmma
@emotion/react 11.9.0Outdated
> Simple styling in React.
+1
emmatown
tkh44
emotion-release-bot
shallowequal 1.1.0
Like lodash isEqualWith but for shallow equal.
tiny-warning 1.0.2 - 1.0.3
A tiny warning function
alexreardon
alexreardon
raf 3.4.0 - 3.4.1
requestAnimationFrame polyfill for node and the browser
polished 4.2.2Outdated
A lightweight toolset for writing styles in Javascript.
d3-interpolate 1.1.1 - 3.0.1
Interpolate numbers, colors, strings, arrays, objects, whatever!
graphql-tag 2.12.6
A JavaScript template literal tag that parses GraphQL queries
jnwng
abernix
apollo-bot
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
@sentry/browser 7.16.0Outdated
Official Sentry SDK for browsers
+8
benvinegar
billyvg
mitsuhiko
styled-components 4.0.0 - 5.3.6Outdated
CSS for the <Component> Age. Style components your way with speed, strong typing, and flexibility.
react-popper 2.3.0
Official library to use Popper on React projects
react-select 5.2.2 - 5.5.6Outdated
A Select control built with and for ReactJS
@emotion/stylis 0.8.4 - 0.8.5
A custom build of Stylis
+1
emmatown
tkh44
emotion-release-bot
use-isomorphic-layout-effect 1.0.0 - 1.1.2
A React helper hook for scheduling a layout effect with a fallback to a regular effect for environments where layout effects should not be used (such as server-side rendering).
andarist
andarist
ts-invariant 0.7.4 - 0.8.2Outdated
TypeScript implementation of invariant(condition, message)
zen-observable 0.8.15Outdated
An Implementation of ES Observables
zenparsing
zenparsing
@formatjs/ecma402-abstract 1.11.0 - 1.11.6Outdated
A collection of implementation for ECMAScript abstract operations
@wry/trie 0.2.1 - 0.3.2Outdated
https://en.wikipedia.org/wiki/Trie
hyphenate-style-name 1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
@wry/equality 0.5.2Outdated
Structural equality checking for JavaScript values
benjamn
benjamn
intl-messageformat 9.12.0 - 10.0.1Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
@wry/context 0.4.4 - 0.6.1Outdated
Manage contextual information needed by (a)synchronous tasks without explicitly passing objects around
benjamn
benjamn
tabbable 6.0.0Outdated
Returns an array of all tabbable DOM nodes within a containing node.
davidtheclark
stefcameron
optimism 0.16.1Outdated
Composable reactive caching with efficient invalidation.
web-vitals 3.0.0 - 3.0.4Outdated
Easily measure performance metrics in JavaScript
@formatjs/icu-messageformat-parser 2.1.0 - 2.1.2Outdated
Hand-written ICU MessageFormat parser with compatible output as [`intl-messageformat-parser`](https://www.npmjs.com/package/intl-messageformat-parser) but 6 - 10 times as fast.
longlho
redonkulus
pyrocat
@apollo/client 3.3.21Outdated
A fully-featured caching GraphQL client.
@formatjs/icu-skeleton-parser 1.3.0 - 1.3.8Outdated
longlho
redonkulus
pyrocat
mdast-util-gfm-strikethrough 0.1.0 - 0.2.3Outdated
mdast extension to parse and serialize GFM strikethrough
@formatjs/fast-memoize 1.2.0 - 1.2.3Outdated
fork of fast-memoize and support esm
@angular/router 10.0.0 - 14.1.3Outdated
Angular - the routing library
formik 2.2.7 - 2.2.9Outdated
Build forms in React, without the tears
jss 10.9.0Outdated
A lib for generating Style Sheets with JavaScript.
is-in-browser 1.1.3Outdated
Simple check to see if current app is running in browser
tuxsudo
tuxsudo
react-draggable 4.4.1 - 4.4.5Outdated
React draggable component
css-vendor 2.0.8
CSS vendor prefix detection and property feature testing.
jss-plugin-nested 10.9.0Outdated
JSS plugin that enables support for nested selectors
jss-plugin-global 10.9.0Outdated
Global styles for JSS
jss-plugin-camel-case 10.8.0 - 10.9.0Outdated
JSS plugin that allows to write camel cased rule properties
jss-plugin-default-unit 10.8.0 - 10.9.0Outdated
JSS plugin that adds default custom unit to numeric values where needed
jss-plugin-rule-value-function 10.8.0 - 10.9.0Outdated
JSS plugin for function value and rule syntax
jss-plugin-vendor-prefixer 10.8.0 - 10.9.0Outdated
JSS plugin that handles vendor prefixes in the browser
jss-plugin-props-sort 10.0.0 - 10.9.0Outdated
JSS plugin that ensures style properties extend each other instead of override
parse-srcset 1.0.0 - 1.0.2
A spec-conformant JavaScript parser for the HTML5 srcset attribute
albell
albell
focus-trap 6.9.2 - 7.0.0Outdated
Trap focus within a DOM node.
react-intl 6.0.1 - 6.0.3Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
@material-ui/utils 4.11.3
Material-UI Utils - Utility functions for Material-UI.
react-bootstrap 2.5.0Outdated
Bootstrap 5 components built with React
rc-trigger 4.3.0 - 4.3.4Outdated
base abstract trigger component for react
@material-ui/core 4.12.4
React components that implement Google's Material Design.
load-script 1.0.0 - 2.0.0
Dynamic script loading for browser
@material-ui/system 4.11.3 - 4.12.2
Material-UI System - Design system for Material-UI.
@formatjs/intl 2.2.5Outdated
Internationalize JS apps. This library provides an API to format dates, numbers, and strings, including pluralization and handling translations.
@material-ui/styles 4.11.1 - 4.11.5
Material-UI Styles - The styling solution of Material-UI.
@stripe/react-stripe-js x.x.x
React components for Stripe.js and Stripe Elements
nprogress 0.2.0
Simple slim progress bars
rstacruz
rstacruz
focus-trap-react 9.0.2 - 10.0.0Outdated
A React component that traps focus.
@chakra-ui/theme 2.1.0 - 2.1.3Outdated
The default theme for chakra components
@styled-system/core 5.1.2
jxnblk
jxnblk
styled-system 5.1.2 - 5.1.5
Responsive, theme-based style props for building design systems with React
@styled-system/css 5.1.5
Styled System for the `css` prop
@styled-system/color 5.0.0 - 5.1.2
jxnblk
jxnblk
@styled-system/layout 5.0.23 - 5.1.2
jxnblk
jxnblk
@styled-system/border 5.1.5
jxnblk
jxnblk
@styled-system/variant 5.1.0 - 5.1.5
Read the docs: https://styled-system.com/variants
jxnblk
jxnblk
@styled-system/space 5.0.18 - 5.1.2
jxnblk
jxnblk
@styled-system/typography 5.0.0 - 5.1.2
jxnblk
jxnblk
@styled-system/position 5.0.15 - 5.1.2
jxnblk
jxnblk
@styled-system/flexbox 5.0.0 - 5.1.2
jxnblk
jxnblk
@styled-system/grid 5.0.0 - 5.1.2
jxnblk
jxnblk
@styled-system/background 5.0.0 - 5.1.2
jxnblk
jxnblk
@styled-system/shadow 5.0.0 - 5.1.2
jxnblk
jxnblk
react-swipeable 7.0.0Outdated
React Swipe event handler hook
bootstrap-vue 2.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
semantic-ui-react 1.1.0Outdated
The official Semantic-UI-React integration.
layershifter
levithomason
react-instantsearch-dom 5.4.0 - 6.38.0Outdated
⚡ Lightning-fast search for React DOM, by Algolia
react-flip-move 3.0.4Outdated
Effortless animation between DOM changes (eg. list reordering) using the FLIP technique.
react-apollo 2.5.0 - 2.5.8Outdated
React Apollo Hooks, Components, and HOC.
reakit 0.14.6 - 0.15.13Outdated
Toolkit for building accessible rich web apps with React
nuka-carousel 4.7.0 - 4.7.3Outdated
Pure React Carousel
@apollo/react-components 3.0.0 - 3.1.5Outdated
React Apollo Query, Mutation and Subscription components.
tesseract.js 2.0.0 - 3.0.3Outdated
Pure Javascript Multilingual OCR
+1
antimatter15
jeromewu
bijection
payment 2.4.5 - 2.4.6
A general purpose library for building credit card forms, validating inputs and formatting numbers. Base on jquery.payment by @stripe, but without the jQuery.
@styled-system/theme-get 5.0.0 - 5.1.2
The `themeGet` function is an existential getter function that can be used in any style declaration to get a value from your theme, with support for fallback values. This helps prevent errors from throwing when a theme value is missing, which can be helpf
jxnblk
jxnblk
qj 2.0.0
A minimal jQuery replacement used in Card and Payment.
jessepollak
jessepollak
@tannin/plural-forms 1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
aduth
@styled-system/prop-types 5.0.18 - 5.1.5
Add prop types to components built with Styled System
jxnblk
jxnblk
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
airnan
airnan
botframework-webchat-component 4.7.0 - 4.15.4Outdated
React component of botframework-webchat
+2
botframework
sgellock
cwhitten
@iabtcf/cmpapi 1.0.0 - 1.5.3Outdated
Ensures other in-page digital marketing technologies have access to CMP transparency and consent information for the iab. Transparency and Consent Framework (TCF).
@swc/helpers x.x.x
@styled-icons/fa-brands x.x.x
@styled-icons/fa-solid x.x.x
@styled-icons/material x.x.x
@styled-icons/styled-icon x.x.x
@styled-icons/boxicons-regular x.x.x
requestanimationframe-timer x.x.x
react-scrollchor x.x.x
currency-symbol-map x.x.x
@styled-icons/feather x.x.x
@styled-icons/icomoon x.x.x
@styled-icons/remix-line x.x.x
country-currency-emoji-flags x.x.x
react-geosuggest x.x.x
@styled-icons/octicons x.x.x