staples.com 71 packages

Last scanned on Oct 27 at 06:12 PM
crypto-js 3.1.2 - 4.1.1VulnerableOutdated
JavaScript library of crypto standards.
License
MIT
Footprint
1 KB
Vulnerabilities
crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
Affected versions >=0 <4.2.0
Matched Modules
Version distribution in production
457
4.1.0
457
4.1.1
185
3.3.0
162
3.1.8
143
3.2.1
143
4.0.0
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
next 10.0.0 - 10.2.3VulnerableOutdated
The React Framework
rauchg
timneutkens
vercel-release-bot
engine.io-client 0.4.0 - 0.7.10VulnerableOutdated
Client for the realtime Engine
rauchg
darrachequesne
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
readable-stream 3.6.0Outdated
Node.js Streams, a user-land copy of the stream library from Node.js
string_decoder 1.1.0 - 1.3.0
The string_decoder module from Node core
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is 16.3.0 - 17.0.2Outdated
Brand checking of React Elements.
inherits 2.0.4
Browser-friendly inheritance fully compatible with standard node.js inherits()
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
entities 2.0.0Outdated
Encode & decode XML and HTML entities with ease & speed
@babel/runtime 7.18.2 - 7.19.4Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
path-to-regexp 6.1.0 - 6.2.0Outdated
Express style path to RegExp utility
yaml 1.0.0 - 2.1.3Outdated
JavaScript parser and stringifier for YAML
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
minimalistic-assert 1.0.0 - 1.0.1
minimalistic-assert ===
cwmma
indutny
@emotion/unitless 0.7.2 - 0.8.0Outdated
An object of css properties that don't accept values with units
+1
emmatown
tkh44
emotion-release-bot
query-string 2.3.0 - 5.0.1Outdated
Parse and stringify URL query strings
sha.js 2.4.9 - 2.4.11
Streamable SHA hashes in pure javascript
dcousens
ljharb
cwmma
underscore 1.11.0 - 1.13.6
JavaScript's functional programming helper library.
asn1.js 5.2.0 - 5.4.1
ASN.1 encoder and decoder
hash-base 3.0.4 - 3.1.0
abstract base class for hash-streams
elliptic 6.5.4Outdated
EC cryptography
hash.js 1.1.2 - 1.1.7
Various hash functions that could be run by both browser and node
hmac-drbg 1.0.1
Deterministic random bit generator (hmac)
lodash-es 4.17.21
Lodash exported as ES modules.
redux 4.0.1 - 4.2.0Outdated
Predictable state container for JavaScript apps
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
des.js 1.0.1Outdated
DES implementation
md5.js 1.1.0 - 1.3.5
node style md5 on pure JavaScript
pbkdf2 3.1.0 - 3.1.2
This library provides the functionality of PBKDF2 with the ability to use any supported hashing algorithm returned from crypto.getHashes()
cipher-base 1.0.4
abstract base class for crypto-streams
parse-asn1 5.1.6Outdated
utility library for parsing asn1 files for use with browserify-sign.
+2
dcousens
ljharb
cwmma
browserify-sign 2.4.0 - 2.8.0Outdated
adds node crypto signing for browsers
+2
dcousens
ljharb
cwmma
browserify-aes 0.4.0 - 0.8.1Outdated
aes, for browserify
stream-http 2.8.2 - 2.8.3Outdated
Streaming http in the browser
evp_bytestokey 1.0.3
The insecure key derivation algorithm from OpenSSL
browserify-rsa 4.1.0
RSA for browserify
+2
dcousens
ljharb
cwmma
create-ecdh 3.0.0 - 4.0.4
createECDH but browserifiable
public-encrypt 4.0.3
browserify version of publicEncrypt & privateDecrypt
+2
dcousens
ljharb
cwmma
diffie-hellman 1.1.2Outdated
pure js diffie-hellman
browserify-des 1.0.2
browserify-des ===
dcousens
ljharb
cwmma
miller-rabin 1.1.0 - 4.0.1
Miller Rabin algorithm for primality test
randomfill 1.0.0 - 1.0.4
random fill from browserify stand alone
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
reselect 4.1.0 - 4.1.6Outdated
Selectors for Redux.
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
to-arraybuffer 1.0.1
Get an ArrayBuffer from a Buffer as fast as possible
@vue/shared 3.0.0 - 3.2.41Outdated
internal utils shared across @vue packages
styled-components 5.2.0 - 5.3.6Outdated
CSS for the <Component> Age. Style components your way with speed, strong typing, and flexibility.
js-base64 2.6.4Outdated
Yet another Base64 transcoder in pure-JS
dankogai
dankogai
@emotion/stylis 0.8.1Outdated
A custom build of Stylis
+1
emmatown
tkh44
emotion-release-bot
intl-messageformat 7.5.1 - 8.3.6Outdated
Formats ICU Message strings with number, date, plural, and select placeholders to create localized messages.
@mui/material 5.0.0 - 5.10.11Outdated
Material UI is an open-source React component library that implements Google's Material Design. It's comprehensive and can be used in production out of the box.
xss 1.0.13 - 1.0.14Outdated
Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
cssfilter 0.0.10
Sanitize untrusted CSS with a configuration specified by a Whitelist. 根据白名单过滤CSS
fp-ts 2.6.6 - 2.9.5Outdated
Functional programming in TypeScript
react-side-effect 2.1.0 - 2.1.2
Create components whose prop changes map to a global side effect
react-intl 3.1.0 - 5.6.9Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
universal-cookie 2.0.1 - 4.0.4Outdated
Universal cookies for JavaScript
intl-messageformat-parser 2.0.0 - 2.1.0Outdated
Parses ICU Message strings into an AST via JavaScript.
rc-trigger 4.3.0 - 4.3.4Outdated
base abstract trigger component for react
react-tooltip 4.2.21Outdated
react tooltip component
perfect-scrollbar 1.5.2 - 1.5.5
Minimalistic but perfect custom scrollbar plugin
react-device-detect 1.8.6 - 1.17.0Outdated
Detect device type and render your component according to it
redux-form 7.0.2 - 8.3.8Outdated
A higher order component decorator for forms using Redux and React
semantic-ui-react 0.64.0 - 0.79.1Outdated
The official Semantic-UI-React integration.
layershifter
levithomason
react-places-autocomplete 7.3.0
A React component for Google Maps Places Autocomplete
@atlaskit/button 15.0.0 - 15.1.5Outdated
A button triggers an event or action. They let users know what will happen next.
atlaskit
atlaskit
botframework-webchat-component 4.14.1 - 4.15.4Outdated
React component of botframework-webchat
+2
botframework
sgellock
cwhitten