postman.com 176 packages

Last scanned on Oct 27 at 06:19 PM
url-parse 1.4.3VulnerableOutdated
Small footprint URL parser that works seamlessly across Node.js and browser environments
License
MIT
Footprint
3 KB
Vulnerabilities
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
Affected versions >=0 <1.5.9
Authorization bypass in url-parse
Affected versions >=0 <1.5.6
Path traversal in url-parse
Affected versions >=0 <1.5.0
Open redirect in url-parse
Affected versions >=0 <1.5.2
Authorization Bypass Through User-Controlled Key in url-parse
Affected versions >=0 <1.5.8
url-parse Incorrectly parses URLs that include an '@'
Affected versions >=0 <1.5.7
Improper Validation and Sanitization in url-parse
Affected versions >=0 <1.4.5
Matched Modules
Version distribution in production
206
1.5.10
167
1.5.9
50
1.5.3
47
1.4.6
47
1.4.7
21
1.4.3
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
marked 0.7.0VulnerableOutdated
A markdown parser built for speed
browserify-sign 4.2.0 - 4.2.1VulnerableOutdated
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
postcss 7.0.39VulnerableOutdated
Tool for transforming styles with JS plugins
sanitize-html 1.20.1VulnerableOutdated
Clean up user-submitted HTML, preserving allowlisted elements and allowlisted attributes on a per-element basis
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
semver 2.0.1 - 5.6.0Outdated
The semantic version parser used by npm.
+2
npm-cli-ops
saquibkhan
fritzy
tslib 2.3.1Outdated
Runtime library for TypeScript helper functions
source-map 0.6.1Outdated
Generates and consumes source maps
+16
tigleym
nbaumgardner
eemeli
readable-stream 2.3.7Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
safe-buffer 5.2.1
Safer Node.js Buffer API
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
uuid 7.0.0 - 8.0.0Outdated
RFC4122 (v1, v4, and v5) UUIDs
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.13.1Outdated
Brand checking of React Elements.
punycode 1.4.1Outdated
A robust Punycode converter that fully complies to RFC 3492 and RFC 5891, and works on nearly all JavaScript platforms.
inherits 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
is-stream 1.0.0 - 3.0.0Outdated
Check if something is a Node.js stream
buffer 4.9.1Outdated
Node.js Buffer API, for the browser
regenerator-runtime 0.13.9Outdated
Runtime for Regenerator-compiled generator and async functions.
picocolors 0.2.0 - 1.0.0
The tiniest and the fastest library for terminal output formatting with ANSI colors
entities 1.1.2Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.12.13 - 7.18.0Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
async 2.6.4Outdated
Higher-order functions and common patterns for asynchronous code
path-to-regexp 0.1.7Outdated
Express style path to RegExp utility
core-util-is 1.0.2 - 1.0.3
The `util.is*` functions introduced in Node v0.12.
ieee754 1.2.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
util-deprecate 1.0.2
The Node.js `util.deprecate()` function with browser support
safer-buffer 2.1.2
Modern Buffer API polyfill without footguns
chalker
chalker
object-assign 4.1.1
ES2015 `Object.assign()` ponyfill
domutils 1.7.0Outdated
Utilities for working with htmlparser2's dom
base64-js 1.5.1
Base64 encoding/decoding in pure JS
dom-serializer 0.2.2Outdated
render domhandler DOM nodes to a string
domhandler 2.4.2Outdated
Handler for htmlparser2 that turns pages into a dom
bn.js 5.2.0Outdated
Big number implementation in pure javascript
events 3.3.0
Node's event emitter for all engines.
domelementtype 1.2.0 - 1.3.1Outdated
all the types of nodes in htmlparser2's dom
process-nextick-args 2.0.1
process.nextTick but always with args
cwmma
cwmma
util 0.11.1Outdated
Node.js's util module for all engines
htmlparser2 3.10.1Outdated
Fast & forgiving HTML/XML parser
xtend 4.0.1 - 4.0.2
extend like a boss
requires-port 1.0.0
Check if a protocol requires a certain port number to be added to an URL.
scheduler 0.19.1Outdated
Cooperative scheduler for the browser environment.
randombytes 2.1.0
random bytes from browserify stand alone
prop-types 15.7.0 - 15.7.2Outdated
Runtime type checking for React props and similar objects.
react 16.14.0Outdated
React is a JavaScript library for building user interfaces.
process 0.11.10
process information for node.js and browsers
react-dom 16.14.0Outdated
React package for working with the DOM.
querystringify 2.2.0
Querystringify - Small, simple but powerful query string parser.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
moment 2.29.4Outdated
Parse, validate, manipulate, and display dates
url 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
lodash.isplainobject 4.0.6
The lodash method `_.isPlainObject` exported as a module.
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
@emotion/memoize 0.7.5Outdated
emotion's memoize utility
+1
emmatown
tkh44
emotion-release-bot
setimmediate 1.0.5
A shim for the setImmediate efficient script yielding API
domenic
domenic
hoist-non-react-statics 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
@emotion/unitless 0.7.2 - 0.7.5Outdated
An object of css properties that don't accept values with units
+1
emmatown
tkh44
emotion-release-bot
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
lodash.isstring 4.0.1
The lodash method `_.isString` exported as a module.
stylis 4.0.13Outdated
A Light–weight CSS Preprocessor
andarist
thysultan
@emotion/is-prop-valid 0.8.8Outdated
A function to check whether a prop is valid for HTML and SVG elements
+1
emmatown
tkh44
emotion-release-bot
ua-parser-js 0.7.31Outdated
Detect Browser, Engine, OS, CPU, and Device type/model from User-Agent & Client Hints data. Supports browser & node.js environment
fast-safe-stringify 2.1.1
Safely and quickly serialize JavaScript objects
lodash.camelcase 4.3.0
The lodash method `_.camelCase` exported as a module.
@emotion/hash 0.8.0Outdated
A MurmurHash2 implementation
+1
emmatown
tkh44
emotion-release-bot
sha.js 2.4.10 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
underscore 1.12.1Outdated
JavaScript's functional programming helper library.
stack-trace 0.0.3 - 0.0.9Outdated
Get v8 stack traces as an array of CallSite objects.
+3
felixge
sebastianhoitz
tim-smart
@emotion/serialize 1.0.2Outdated
serialization utils for emotion
+1
emmatown
tkh44
emotion-release-bot
@popperjs/core 2.11.1 - 2.11.2Outdated
Tooltip and Popover Positioning Engine
@emotion/utils 1.0.0Outdated
internal utils for emotion
+1
emmatown
tkh44
emotion-release-bot
stream-browserify 1.0.0 - 2.0.2Outdated
the stream module from node core for browsers
winston 3.1.0Outdated
A logger for just about everything.
asn1.js 5.3.0 - 5.4.1
ASN.1 encoder and decoder
memoize-one 5.2.1Outdated
A memoization library which only remembers the latest invocation
lodash.clonedeep 4.5.0
The lodash method `_.cloneDeep` exported as a module.
hash-base 3.1.0
abstract base class for hash-streams
elliptic 6.5.4Outdated
EC cryptography
hash.js 1.1.7
Various hash functions that could be run by both browser and node
@emotion/cache 11.7.1Outdated
emotion's cache
+1
emmatown
tkh44
emotion-release-bot
@emotion/sheet 1.1.0Outdated
emotion's stylesheet
+1
emmatown
tkh44
emotion-release-bot
@emotion/weak-memoize 0.2.1 - 0.2.5Outdated
A memoization function that uses a WeakMap
+1
emmatown
tkh44
emotion-release-bot
brorand 1.1.0
Random number generator for browsers and node.js
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
minimalistic-crypto-utils 1.0.1
Minimalistic tools for JS crypto modules
des.js 1.0.1Outdated
DES implementation
ripemd160 2.0.2
Compute ripemd160 of bytes or strings.
array-uniq 0.1.1 - 1.0.3Outdated
Create an array without duplicates
warning 4.0.3
A mirror of Facebook's Warning
winston-transport 4.4.0Outdated
Base stream implementations for winston@3 and up.
md5.js 1.3.5
node style md5 on pure JavaScript
pbkdf2 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
parse-asn1 5.1.6Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
cipher-base 1.0.4
abstract base class for crypto-streams
buffer-xor 1.0.0 - 1.0.3Outdated
A simple module for bitwise-xor on buffers
create-hash 1.2.0
create hashes for browserify
browserify-aes 1.2.0
aes, for browserify
logform 1.10.0Outdated
An mutable object-based log format designed for chaining & objectMode streams.
stream-http 2.8.3Outdated
Streaming http in the browser
create-hmac 1.1.6 - 1.1.7
node style hmacs in the browser
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 4.1.0
RSA for browserify
+2
dcousens
ljharb
cwmma
timers-browserify 2.0.10 - 2.0.12
timers module for browserify
crypto-browserify 1.0.9 - 2.0.0Outdated
implementation of crypto for the browser
+2
dcousens
ljharb
cwmma
create-ecdh 4.0.2 - 4.0.4
createECDH but browserifiable
https-browserify 1.0.0
https module compatability for browserify
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
diffie-hellman 5.0.2 - 5.0.3
pure js diffie-hellman
browserify-des 1.0.2
browserify-des ===
dcousens
ljharb
cwmma
triple-beam 1.2.0 - 1.3.0Outdated
Definitions of levels for logging purposes & shareable Symbol constants.
browserify-cipher 1.0.1
ciphers for the browser
cwmma
cwmma
miller-rabin 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.3 - 1.0.4
random fill from browserify stand alone
enabled 1.0.2Outdated
Check if a certain debug flag is enabled.
builtin-status-codes 3.0.0
The map of HTTP status codes from the builtin http module
one-time 0.0.4Outdated
Run the supplied function exactly one time (once)
@emotion/react 11.7.1Outdated
> Simple styling in React.
+1
emmatown
tkh44
emotion-release-bot
shallowequal 1.1.0
Like lodash isEqualWith but for shallow equal.
ufo 0.6.1 - 0.8.6Outdated
URL utils for humans
pi0
pi0
serialize-error 2.1.0Outdated
Serialize/deserialize an error into a plain object
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
fb
sophiebits
to-arraybuffer 1.0.1
Get an ArrayBuffer from a Buffer as fast as possible
p-is-promise 3.0.0 - 4.0.0
Check if something is a promise
styled-components 5.1.0 - 5.1.1Outdated
CSS for the <Component> Age. Style components your way with speed, strong typing, and flexibility.
react-popper 0.10.1 - 0.10.4Outdated
Official library to use Popper on React projects
react-select 5.2.2Outdated
A Select control built with and for ReactJS
lodash.isfunction 3.0.9
The Lodash method `_.isFunction` exported as a module.
@emotion/stylis 0.8.4 - 0.8.5
A custom build of Stylis
+1
emmatown
tkh44
emotion-release-bot
lodash.mergewith 4.6.2
The Lodash method `_.mergeWith` exported as a module.
popper.js 1.16.1
A kickass library to manage your poppers
lodash.escaperegexp 4.1.2
The lodash method `_.escapeRegExp` exported as a module.
lodash.isobject 3.0.2
The modern build of lodash’s `_.isObject` as a module.
web-vitals 2.1.2Outdated
Easily measure performance metrics in JavaScript
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
+1
fb
timer
iansu
jss 5.3.0 - 5.5.5Outdated
A lib for generating Style Sheets with JavaScript.
exenv 1.2.1 - 1.2.2
React's ExecutionEnvironment module extracted for use in other packages & components
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
qrcode 0.8.0 - 0.8.2Outdated
QRCode / 2d Barcode api with both server side and client side support using canvas
@sentry/webpack-plugin x.x.x
Official Sentry Webpack plugin
tippy.js 6.3.7
The complete tooltip, popover, dropdown, and menu solution for the web
create-react-class 15.7.0
Legacy API for creating React components.
react-use 8.1.2 - 13.24.1Outdated
Collection of React Hooks
streamich
streamich
@ctrl/tinycolor 2.1.0 - 3.4.1Outdated
Fast, small color manipulation and conversion for JavaScript
react-modal 3.13.1Outdated
Accessible modal dialog component for React.JS
react-bootstrap 0.30.2 - 1.0.1Outdated
Bootstrap 5 components built with React
mobx 5.8.0Outdated
Simple, scalable state management.
react-table 7.0.0 - 7.8.0
Hooks for building lightweight, fast and extendable datagrids for React
mobx-react-lite 1.4.0Outdated
Lightweight React bindings for MobX based on React 16.8+ and Hooks
mobx-react 6.1.0Outdated
React bindings for MobX. Create fully reactive components.
launchdarkly-js-client-sdk 2.19.2Outdated
LaunchDarkly SDK for JavaScript
@auth0/auth0-spa-js 2.0.0Outdated
Auth0 SDK for Single Page Applications using Authorization Code Grant Flow with PKCE
backbone 1.3.3Outdated
Give your JS App some Backbone with Models, Views, Collections, and Events.
srcset 1.0.0Outdated
Parse and stringify the HTML `<img>` srcset attribute
mousetrap 1.6.0Outdated
Simple library for handling keyboard shortcuts
@tippyjs/react 4.2.0Outdated
React component for Tippy.js
launchdarkly-react-client-sdk 2.23.0Outdated
LaunchDarkly SDK for React
reactstrap 6.4.0 - 8.10.1Outdated
React Bootstrap components
gatsby 4.24.0 - 4.24.5Outdated
Blazing fast modern site generator for React
bootstrap-vue 2.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
react-from-dom 0.6.0 - 0.6.2Outdated
Convert HTML/XML source code or DOM nodes to React elements
@splitsoftware/splitio 10.9.0 - 10.17.3Outdated
Split SDK
vue-gtag 1.14.1 - 2.0.1
Global Site Tag (gtag.js) plugin for Vue
vuex-class 0.1.0 - 0.2.0Outdated
Binding helpers for Vuex and vue-class-component
@tannin/plural-forms 1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
aduth
react-notification-system 0.2.17Outdated
A React Notification System fully customized
react-facebook 4.1.1 - 5.0.3Outdated
Facebook components like a Login button, Like, Share, Comments, Embedded Post/Video, Messenger Chat and others
most 0.17.1 - 0.19.7Outdated
Monadic streams
woothee 0.3.0 - 1.11.1
User-Agent string parser (js implementation)
tagomoris
tagomoris
botframework-webchat-component 4.7.0 - 4.15.4Outdated
React component of botframework-webchat
+2
botframework
sgellock
cwhitten
prebid.js 0.13.0 - 7.22.0Outdated
Header Bidding Management Library
@postman/aether-design-tokens x.x.x
@postman/aether-icons x.x.x
@postman/aether x.x.x
circular-json x.x.x