pistonheads.com 85 packages

Last scanned on Jan 19 at 07:54 AM
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
License
MIT
Footprint
2 KB
Vulnerabilities
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
4.17.16
946
4.17.21
337
4.17.20
322
4.17.15
302
4.17.19
301
4.17.13
next-auth 2.0.0 - 4.0.0VulnerableOutdated
Authentication for Next.js
next 12.3.0 - 12.3.4VulnerableOutdated
The React Framework
rauchg
timneutkens
vercel-release-bot
tslib 1.6.0 - 2.4.1Outdated
Runtime library for TypeScript helper functions
react-is 16.3.0 - 16.13.1Outdated
Brand checking of React Elements.
@babel/runtime 7.14.0 - 7.16.3Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
get-intrinsic 1.1.0 - 1.1.1Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
path-to-regexp 6.1.0 - 6.2.0Outdated
Express style path to RegExp utility
cookie 0.2.4 - 0.4.1Outdated
HTTP server cookie parsing and serialization
dougwilson
dougwilson
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
object-inspect 1.11.0 - 1.11.1Outdated
string representations of objects in node and the browser
has-symbols 1.0.0 - 1.0.3
Determine if the JS environment has Symbol support. Supports spec, or shams.
es-abstract 1.19.0 - 1.19.1Outdated
ECMAScript spec abstract operations.
define-properties 1.1.3 - 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
is-callable 1.1.4 - 1.2.4Outdated
Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.
has-tostringtag 1.0.0Outdated
Determine if the JS environment has `Symbol.toStringTag` support. Supports spec, or shams.
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
object-keys 1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
is-regex 1.1.4
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
is-date-object 1.0.1 - 1.0.3Outdated
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
es-to-primitive 1.2.0 - 1.2.1
ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
tarruda
tarruda
scheduler 0.15.0 - 0.23.0
Cooperative scheduler for the browser environment.
prop-types 15.7.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 17.0.0 - 18.2.0
React is a JavaScript library for building user interfaces.
object.fromentries 2.0.3 - 2.0.6Outdated
ES proposal-spec-compliant Object.fromEntries shim.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
clsx 1.1.0 - 1.2.1Outdated
A tiny (239B) utility for constructing className strings conditionally.
@emotion/memoize 0.7.5 - 0.8.0Outdated
emotion's memoize utility
+1
emmatown
tkh44
emotion-release-bot
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
@emotion/unitless 0.7.2 - 0.8.0Outdated
An object of css properties that don't accept values with units
+1
emmatown
tkh44
emotion-release-bot
classnames 2.2.6Outdated
A simple utility for conditionally joining classNames together
query-string 6.5.0 - 7.1.3Outdated
Parse and stringify URL query strings
ua-parser-js 0.7.24Outdated
Detect Browser, Engine, OS, CPU, and Device type/model from User-Agent & Client Hints data. Supports browser & node.js environment
@emotion/hash 0.8.0 - 0.9.0Outdated
A MurmurHash2 implementation
+1
emmatown
tkh44
emotion-release-bot
graphql 14.4.2 - 15.0.0Outdated
A Query Language and Runtime which can target any service.
@emotion/serialize 1.0.2 - 1.1.1Outdated
serialization utils for emotion
+1
emmatown
tkh44
emotion-release-bot
lodash.isequal 4.5.0
The Lodash method `_.isEqual` exported as a module.
memoize-one 5.1.0 - 5.1.1Outdated
A memoization library which only remembers the latest invocation
immediate 2.4.3 - 3.3.0
A cross browser microtask library
cwmma
cwmma
@storybook/theming 6.5.0 - 6.5.15Outdated
Core Storybook Components
lodash-es 4.17.20 - 4.17.21
Lodash exported as ES modules.
filter-obj 1.1.0Outdated
Filter object keys and values into a new object
babel-runtime 5.0.13 - 6.0.14Outdated
babel selfContained runtime
hzoo
loganfsmyth
existentialism
graphql-tag 2.12.2 - 2.12.6
A JavaScript template literal tag that parses GraphQL queries
jnwng
abernix
apollo-bot
split-on-first 1.0.0 - 1.1.0Outdated
Split a string on the first occurance of a given separator
markdown-it 4.0.0 - 13.0.1Outdated
Markdown-it - modern pluggable markdown parser.
resize-observer-polyfill 1.5.0 - 1.5.1
A polyfill for the Resize Observer API
react-select 5.0.0 - 5.5.4Outdated
A Select control built with and for ReactJS
lodash.throttle 4.1.1
The lodash method `_.throttle` exported as a module.
zen-observable-ts 1.1.0 - 1.2.3
Thin wrapper around zen-observable and @types/zen-observable, to support ESM exports as well as CommonJS exports
jbaxleyiii
apollo-bot
@wry/trie 0.2.1 - 0.3.2Outdated
https://en.wikipedia.org/wiki/Trie
@mui/utils 5.8.0 - 5.8.4Outdated
Utility functions for React components.
@wry/equality 0.5.1 - 0.5.3Outdated
Structural equality checking for JavaScript values
benjamn
benjamn
@mui/system 5.6.3 - 5.8.0Outdated
MUI System is a set of CSS utilities to help you build custom designs more efficiently. It makes it possible to rapidly lay out custom designs.
@mui/material 5.5.1 - 5.7.0Outdated
Material UI is an open-source React component library that implements Google's Material Design. It's comprehensive and can be used in production out of the box.
@wry/context 0.4.0 - 0.6.1Outdated
Manage contextual information needed by (a)synchronous tasks without explicitly passing objects around
benjamn
benjamn
optimism 0.16.1 - 0.16.2Outdated
Composable reactive caching with efficient invalidation.
@reduxjs/toolkit 1.6.0 - 1.9.1Outdated
The official, opinionated, batteries-included toolset for efficient Redux development
@apollo/client 3.4.12 - 3.4.17Outdated
A fully-featured caching GraphQL client.
@angular/router 10.0.0 - 14.1.3Outdated
Angular - the routing library
react-draggable 4.4.1 - 4.4.5Outdated
React draggable component
string-convert 0.2.0 - 0.2.1
String convertions
akiran
akiran
json2mq 0.2.0
Generate media query string from JSON or javascript object
akiran
akiran
@react-spring/shared 9.0.0 - 9.6.1Outdated
Globals and shared modules
@react-spring/animated 9.0.0 - 9.6.1Outdated
Animated component props for React
@react-spring/core 9.2.4 - 9.6.1Outdated
The platform-agnostic core of `react-spring`
@fortawesome/fontawesome-svg-core 1.3.0 - 6.1.1Outdated
The iconic font, CSS, and SVG framework
@react-spring/web 9.2.4 - 9.5.5Outdated
`react-dom` support
css-mediaquery 0.1.2
Parses and determines if a given CSS Media Query matches a set of values.
ericf
ericf
@fortawesome/react-fontawesome 0.1.18 - 0.1.19Outdated
Official React component for Font Awesome 5
+4
jasonlundien
devoto13
jrjohnson
react-player 1.12.0 - 1.15.3Outdated
A React component for playing a variety of URLs, including file paths, YouTube, Facebook, Twitch, SoundCloud, Streamable, Vimeo, Wistia and DailyMotion
smoothscroll-polyfill 0.4.4
Smooth Scroll behavior polyfill
@fortawesome/free-brands-svg-icons 6.0.0 - 6.1.2Outdated
The iconic font, CSS, and SVG framework
next-seo 1.0.0 - 4.6.0Outdated
SEO plugin for Next.js projects
react-swipeable 5.0.0 - 7.0.0Outdated
React Swipe event handler hook
serialize-query-params 0.1.1 - 0.1.2Outdated
A library for simplifying encoding and decoding URL query parameters.
crypto-hash 0.1.0 - 2.0.1Outdated
Tiny hashing module that uses the native crypto API in Node.js and the browser
@apollo/react-components 3.0.0 - 3.1.5Outdated
React Apollo Query, Mutation and Subscription components.
tesseract.js 2.0.0 - 4.0.2Outdated
Pure Javascript Multilingual OCR
+1
antimatter15
jeromewu
bijection
@atlaskit/spinner 7.0.0 - 15.3.2Outdated
A spinner is an animated spinning icon that lets users know content is being loaded.
atlaskit
atlaskit
react-cookie-consent 8.0.0 - 8.0.1Outdated
A small, simple and customizable cookie consent bar for use in React applications.
@most/scheduler 0.7.0 - 1.3.0
Reactive programming with lean, functions-only, curried, tree-shakeable API
react-amphtml 3.1.0 - 4.0.2
Use amphtml components inside your React apps easily!
dfrankland
dfrankland