pandora.com 140 packages

Last scanned on Oct 27 at 07:04 PM
crypto-js 3.3.0VulnerableOutdated
JavaScript library of crypto standards.
License
MIT
Footprint
15 KB
Vulnerabilities
crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
Affected versions >=0 <4.2.0
Matched Modules
Version distribution in production
457
4.1.0
457
4.1.1
185
3.3.0
162
3.1.8
143
3.2.1
143
4.0.0
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
tslib 2.4.0Outdated
Runtime library for TypeScript helper functions
react-is 16.13.1Outdated
Brand checking of React Elements.
punycode 1.4.1Outdated
A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.
regenerator-runtime 0.13.9Outdated
Runtime for Regenerator-compiled generator and async functions.
@babel/runtime 7.18.2 - 7.18.3Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
get-intrinsic 1.1.2Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.1Outdated
Implementation of Function.prototype.bind
lodash 4.17.21
Lodash modular utilities.
axios 0.26.1Outdated
Promise based HTTP client for the browser and node.js
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
has-symbols 1.0.2 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
rxjs 7.5.5Outdated
Reactive Extensions for modern JavaScript
has-property-descriptors 1.0.0Outdated
Does the environment have full property descriptor support? Handles IE 8's broken defineProperty/gOPD.
object-assign 4.1.1
ES2015 `Object.assign()` ponyfill
define-properties 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
has-tostringtag 1.0.0Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
object-keys 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
regexp.prototype.flags 1.4.3Outdated
ES6 spec-compliant RegExp.prototype.flags shim.
core-js 3.22.6 - 3.22.7Outdated
Standard library
is-regex 1.1.4
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
is-date-object 1.0.5
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
functions-have-names 1.2.3
Does this JS environment support the `name` property on functions?
has 1.0.2 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
scheduler 0.19.1Outdated
Cooperative scheduler for the browser environment.
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
is-arguments 1.1.1
Is this an arguments object? It's a harder question than you think.
react 16.14.0Outdated
React is a JavaScript library for building user interfaces.
json-stringify-safe 5.0.1
Like JSON.stringify, but doesn't blow up on circular refs.
process 0.11.10
process information for node.js and browsers
react-dom 16.14.0Outdated
React package for working with the DOM.
deep-equal 1.1.0 - 1.1.1Outdated
node's assert.deepEqual algorithm
url 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
immutable 3.8.2Outdated
Immutable Data Collections
object-is 1.1.4 - 1.1.5Outdated
ES2015-compliant shim for Object.is - differentiates between -0 and +0
hoist-non-react-statics 2.5.1 - 2.5.5Outdated
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
invariant 2.2.3 - 2.2.4
invariant
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
query-string 4.3.4Outdated
Parse and stringify URL query strings
ua-parser-js 0.7.31Outdated
Detect Browser, Engine, OS, CPU, and Device type/model from User-Agent & Client Hints data. Supports browser & node.js environment
react-transition-group 1.2.0 - 1.2.1Outdated
A react component toolset for managing animations
graphql 14.4.0 - 16.6.0Outdated
A Query Language and Runtime which can target any service.
dom-helpers 3.4.0Outdated
tiny modular DOM lib for ie9+
whatwg-fetch 3.3.0 - 3.3.1Outdated
A window.fetch polyfill.
jakechampion
mattandrews
mislav
core-js-pure 3.22.6 - 3.22.7Outdated
Standard library
webpack-merge 1.0.0 - 1.0.2Outdated
Variant of merge that's useful for webpack configuration
validator 13.5.1 - 13.7.0Outdated
String validation and sanitization
strict-uri-encode 1.1.0Outdated
A stricter URI encode adhering to RFC 3986
react-router 3.0.0 - 3.2.6Outdated
Declarative routing for React
is-promise 2.2.0 - 4.0.0
Test whether an object looks like a promises-a+ promise
forbeslindesay
then-bot
lodash-es 4.17.3 - 4.17.21
Lodash exported as ES modules.
redux 4.2.0Outdated
Predictable state container for JavaScript apps
react-fast-compare 2.0.4Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
warning 2.0.0 - 3.0.0Outdated
A mirror of Facebook's Warning
crypto-browserify 0.2.0 - 1.0.1Outdated
implementation of crypto for the browser
+2
dcousens
ljharb
cwmma
js-cookie 2.2.1Outdated
A simple, lightweight JavaScript API for handling cookies
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
reselect 2.5.4Outdated
Selectors for Redux.
shallowequal 1.1.0
Like lodash isEqualWith but for shallow equal.
react-redux 5.0.0 - 7.2.9Outdated
Official React bindings for Redux
fbjs 0.8.16 - 0.8.18Outdated
A collection of utility libraries used by other Facebook JS projects
+5
zpao
eliwhite
yungsters
@babel/runtime-corejs3 7.18.3 - 7.19.1Outdated
babel's modular runtime helpers with core-js@3 polyfilling
+1
hzoo
existentialism
nicolo-ribaudo
history 3.3.0Outdated
Manage session history with JavaScript
style-to-object 0.2.0 - 0.2.2Outdated
Parse CSS inline style to JavaScript object.
is-retry-allowed 1.2.0Outdated
Check whether a request can be retried based on the `error.code`
d3-shape 1.0.2 - 3.1.0Outdated
Graphical primitives for visualization, such as lines and areas.
css 2.2.2 - 3.0.0
CSS parser / stringifier
copy-to-clipboard 3.3.0 - 3.3.1Outdated
Copy stuff into clipboard using JS with fallbacks
redux-thunk 1.0.1 - 2.0.1Outdated
Thunk middleware for Redux.
toggle-selection 1.0.5 - 1.0.6
Toggle current selected content in browser
react-select 3.0.1Outdated
A Select control built with and for ReactJS
intl-messageformat 2.1.0 - 2.2.0Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
@mui/system 5.0.5 - 5.10.10Outdated
MUI System is a set of CSS utilities to help you build custom designs more efficiently. It makes it possible to rapidly lay out custom designs.
tabbable 1.1.3Outdated
Returns an array of all tabbable DOM nodes within a containing node.
davidtheclark
stefcameron
@angular/core 2.4.2 - 14.2.8Outdated
Angular - the core framework
angular
google-wombot
@apollo/client 3.0.0 - 3.7.1Outdated
A fully-featured caching GraphQL client.
localforage 1.7.3Outdated
Offline storage, improved.
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
fast-copy 1.0.0 - 1.2.0Outdated
A blazing fast deep object copier
planttheidea
planttheidea
axios-retry 1.1.1 - 3.3.1Outdated
Axios plugin that intercepts failed requests and retries them whenever posible.
softonic
softonic
@hookform/resolvers 1.1.0Outdated
React Hook Form validation resolvers: Yup, Joi, Superstruct, Zod, Vest, Class Validator, io-ts, Nope, computed-types, TypeBox, arktype and Typanion
react-side-effect 1.2.0Outdated
Create components whose prop changes map to a global side effect
react-helmet 5.2.1Outdated
A document head manager for React
create-react-class 15.7.0
Legacy API for creating React components.
react-use 4.2.0 - 17.4.0Outdated
Collection of React Hooks
streamich
streamich
focus-trap 2.4.6Outdated
Trap focus within a DOM node.
react-intl 2.8.0 - 2.9.0Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
intl-messageformat-parser 1.3.0 - 1.5.1Outdated
Parses ICU Message strings into an AST via JavaScript.
html-react-parser 0.4.7Outdated
HTML to React parser.
html-dom-parser 0.1.3 - 0.2.1Outdated
HTML to DOM parser.
react-bootstrap 0.30.2 - 0.33.1Outdated
Bootstrap 5 components built with React
react-tooltip 3.11.6 - 4.0.1Outdated
react tooltip component
react-virtualized 5.3.0 - 6.3.2Outdated
React components for efficiently rendering large, scrollable lists and tabular data
redux-saga 1.0.0 - 1.1.3Outdated
Saga middleware for Redux to handle Side Effects
redux-persist 4.10.0 - 4.10.2Outdated
persist and rehydrate redux stores
andarist
rt2zz
react-device-detect 1.8.6 - 2.2.2Outdated
Detect device type and render your component according to it
@redux-saga/core 1.1.2 - 1.1.3Outdated
Saga middleware for Redux to handle Side Effects
@redux-saga/symbols 1.1.0 - 1.1.2Outdated
Redux-saga internal symbol "registry".
@redux-saga/is 1.1.0 - 1.1.2Outdated
Runtime type checking helpers
yelouafi
andarist
redux-saga-release-bot
@redux-saga/delay-p 1.0.0 - 1.1.2Outdated
Promisified setTimeout
@redux-saga/deferred 1.0.0 - 1.1.2Outdated
Helper for creating "exposed" promise object (with resolve & reject methods).
@bugsnag/js 5.0.0 - 7.18.0Outdated
Universal Javascript error reporting. Automatically detect JavaScript errors in the browser and Node.js, with plugins for React, Vue, Angular, Express, Restify and Koa.
@bugsnag/browser 7.17.0Outdated
Bugsnag error reporter for browser JavaScript
+6
joshedney
ahmed_bugsnag
gingerbenw
focus-trap-react 3.1.3 - 4.0.0Outdated
A React component that traps focus.
mousetrap 1.6.5
Simple library for handling keyboard shortcuts
intl-format-cache 2.2.2 - 3.0.2Outdated
A memoizer factory for Intl format constructors.
redux-immutable 3.1.0Outdated
redux-immutable is used to create an equivalent function of Redux combineReducers that works with Immutable.js state.
react-immutable-proptypes 2.2.0
PropType validators that work with Immutable.js.
chain-function 1.0.1
chain a bunch of functions together into a single call
monastic.panic
monastic.panic
redux-form 7.0.0 - 8.3.8Outdated
A higher order component decorator for forms using Redux and React
bootstrap-vue 1.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
normalizr 2.3.0 - 2.3.1Outdated
Normalizes and denormalizes JSON according to schema for Redux and Flux applications
use-query-params 2.0.0 - 2.1.2Outdated
React Hook for managing state in URL query parameters with easy serialization.
react-router-redux 4.0.8
Ruthlessly simple bindings to keep react-router and redux in sync
redux-observable 2.0.0Outdated
RxJS based middleware for Redux. Compose and cancel async actions and more.
@bugsnag/plugin-react 7.10.0 - 7.18.0Outdated
React integration for @bugsnag/js
+6
joshedney
ahmed_bugsnag
gingerbenw
intl-relativeformat 2.2.0Outdated
Formats JavaScript dates to relative time strings.
adaptivecards 2.10.0 - 2.11.1Outdated
Adaptive Cards Javascript library for HTML Clients
intl-locales-supported 1.8.5 - 1.8.12
Utility to help you polyfill the Node.js runtime when the Intl APIs are missing, or if the built-in Intl is missing locale data that you need.
react-sticky 5.0.6 - 5.0.8Outdated
Sticky component for React
react-dom-core 0.0.2 - 0.1.2Outdated
Copy of react-dom 15
redux-batched-subscribe 0.1.5 - 0.1.6
redux store enhancer which allows batching subscribe notifications.
react-facebook 4.1.1 - 5.0.3Outdated
Facebook components like a Login button, Like, Share, Comments, Embedded Post/Video, Messenger Chat and others
react-redux-loading-bar 2.6.0 - 2.9.3Outdated
Simple Loading Bar for Redux and React
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
airnan
airnan
woothee 0.3.0 - 1.11.1
User-Agent string parser (js implementation)
tagomoris
tagomoris
prebid.js 1.38.0 - 6.23.0Outdated
Header Bidding Management Library
react-lazy-cache x.x.x
remotedev-serialize x.x.x
browser-bunyan x.x.x
redux-dynamic-middlewares x.x.x
redux-persist-transform-immutable x.x.x
jsan x.x.x
@sxmp/registry x.x.x
@sxmp/detector x.x.x
oauthsimple x.x.x
redux-ignore x.x.x
redux-persist-migrate x.x.x
wgxpath x.x.x