stitchfix.com 125 packages

Last scanned on Jan 19 at 08:01 AM
graphql 16.3.0 - 16.5.0VulnerableOutdated
A Query Language and Runtime which can target any service.
License
MIT
Footprint
16 KB
Vulnerabilities
graphql Uncontrolled Resource Consumption vulnerability
Affected versions >=16.3.0 <16.8.1
Matched Modules
Version distribution in production
485
15.8.0
484
15.7.2
438
15.4.0
432
15.7.0
432
15.7.1
289
16.5.0
es5-ext 0.10.24 - 0.10.49VulnerableOutdated
ECMAScript extensions and shims
tslib 1.13.0 - 1.14.1Outdated
Runtime library for TypeScript helper functions
isarray 0.0.0 - 0.0.1Outdated
Array#isArray for older browsers
react-is 16.13.1Outdated
Brand checking of React Elements.
buffer 4.9.2Outdated
Node.js Buffer API, for the browser
@babel/runtime 7.18.2 - 7.18.3Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
lodash 4.17.21
Lodash modular utilities.
path-to-regexp 1.8.0Outdated
Express style path to RegExp utility
fast-deep-equal 3.1.0 - 3.1.3
Fast deep equal
ieee754 1.2.0 - 1.2.1
Read/write IEEE754 floating point numbers from/to a Buffer or array-like object
object-assign 4.1.1
ES2015 `Object.assign()` ponyfill
base64-js 1.5.1
Base64 encoding/decoding in pure JS
fast-json-stable-stringify 2.0.0 - 2.1.0
deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify
core-js 3.20.3 - 3.21.1Outdated
Standard library
scheduler 0.20.2Outdated
Cooperative scheduler for the browser environment.
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 17.0.2Outdated
React is a JavaScript library for building user interfaces.
process 0.11.10
process information for node.js and browsers
react-dom 17.0.2Outdated
React package for working with the DOM.
lower-case 2.0.2Outdated
Transforms the string to lower case
no-case 3.0.4Outdated
Transform any case string into a lower case string with a space between each word
@aws-crypto/sha256-js 1.2.0 - 2.0.1Outdated
A pure JS implementation SHA256.
+5
amzn-oss
seebees
agray256
hoist-non-react-statics 3.3.2
Copies non-react specific statics from a child component to a parent component
mridgway
mridgway
@aws-crypto/util 1.2.2 - 2.0.0Outdated
Helper functions
+5
amzn-oss
seebees
agray256
classnames 2.3.2Outdated
A simple utility for conditionally joining classNames together
react-transition-group 4.4.5
A react component toolset for managing animations
@aws-sdk/util-utf8-browser 3.36.0 - 3.188.0Outdated
A browser UTF-8 string <-> UInt8Array converter
+2
mattsb42-aws
kuhe
amzn-oss
dom-helpers 5.2.1
tiny modular DOM lib for ie9+
@aws-crypto/supports-web-crypto 1.0.0Outdated
Provides functions for detecting if the host environment supports the WebCrypto API
+5
amzn-oss
seebees
agray256
@aws-crypto/sha256-browser 1.2.0 - 2.0.1Outdated
SHA256 wrapper for browsers that prefers `window.crypto.subtle` but will fall back to a pure JS implementation in @aws-crypto/sha256-js to provide a consistent interface for SHA256.
+5
amzn-oss
seebees
agray256
@aws-crypto/ie11-detection 1.0.0Outdated
Provides functions and types for detecting if the host environment is IE11
+5
amzn-oss
seebees
agray256
@popperjs/core 2.11.0Outdated
Tooltip and Popover Positioning Engine
tiny-invariant 0.0.2 - 1.3.1Outdated
A tiny invariant function
is-absolute-url 3.0.3Outdated
Check if a URL is absolute
react-router 5.0.0 - 5.3.4Outdated
Declarative routing for React
lodash-es 4.17.21
Lodash exported as ES modules.
@aws-sdk/util-locate-window 3.0.0 - 3.208.0Outdated
[![NPM version](https://img.shields.io/npm/v/@aws-sdk/util-locate-window/latest.svg)](https://www.npmjs.com/package/@aws-sdk/util-locate-window) [![NPM downloads](https://img.shields.io/npm/dm/@aws-sdk/util-locate-window.svg)](https://www.npmjs.com/packag
+2
mattsb42-aws
kuhe
amzn-oss
upper-case 2.0.2Outdated
Transforms the string to upper case
react-router-dom 5.3.0 - 5.3.3Outdated
Declarative routing for React web applications
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
warning 4.0.3
A mirror of Facebook's Warning
js-cookie 3.0.1Outdated
A simple, lightweight JavaScript API for handling cookies
void-elements 3.1.0
Array of "void elements" defined by the HTML specification.
history 4.10.1Outdated
Manage session history with JavaScript
constant-case 3.0.2 - 3.0.4Outdated
Transform into upper case string with an underscore between words
graphql-tag 2.12.6
A JavaScript template literal tag that parses GraphQL queries
jnwng
abernix
apollo-bot
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
fb
sophiebits
resize-observer-polyfill 1.5.1
A polyfill for the Resize Observer API
i18next 19.9.2Outdated
i18next internationalization framework
d3-timer 1.0.10Outdated
An efficient queue capable of managing thousands of concurrent animations.
d3-ease 1.0.7Outdated
Easing functions for smooth animation.
react-popper 2.2.5Outdated
Official library to use Popper on React projects
zen-observable-ts 0.8.14 - 0.8.21Outdated
Thin wrapper around zen-observable and @types/zen-observable, to support ESM exports as well as CommonJS exports
jbaxleyiii
apollo-bot
@aws-sdk/util-hex-encoding 3.183.0 - 3.201.0Outdated
Converts binary buffers to and from lowercase hexadecimal encoding
+2
amzn-oss
aws-sdk-bot
kuhe
ts-invariant 0.10.1 - 0.10.3
TypeScript implementation of invariant(condition, message)
zen-observable 0.8.15Outdated
An Implementation of ES Observables
zenparsing
zenparsing
@wry/trie 0.2.1 - 0.3.2Outdated
https://en.wikipedia.org/wiki/Trie
hyphenate-style-name 1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
resolve-pathname 3.0.0
Resolve URL pathnames using JavaScript
mjackson
mjackson
@aws-sdk/middleware-retry 3.0.0 - 3.16.0Outdated
[![NPM version](https://img.shields.io/npm/v/@aws-sdk/middleware-retry/latest.svg)](https://www.npmjs.com/package/@aws-sdk/middleware-retry) [![NPM downloads](https://img.shields.io/npm/dm/@aws-sdk/middleware-retry.svg)](https://www.npmjs.com/package/@aws
+2
amzn-oss
aws-sdk-bot
kuhe
value-equal 1.0.1
Are these two JavaScript values equal?
mjackson
mjackson
@wry/equality 0.1.9 - 0.1.11Outdated
Structural equality checking for JavaScript values
benjamn
benjamn
tabbable 4.0.0Outdated
Returns an array of all tabbable DOM nodes within a containing node.
davidtheclark
stefcameron
@wry/context 0.7.0Outdated
Manage contextual information needed by (a)synchronous tasks without explicitly passing objects around
benjamn
benjamn
optimism 0.16.1 - 0.16.2Outdated
Composable reactive caching with efficient invalidation.
react-i18next 11.18.5 - 12.1.4Outdated
Internationalization for react done right. Using the i18next i18n ecosystem.
@angular/core 2.4.2 - 15.1.1Outdated
Angular - the core framework
angular
google-wombot
@apollo/client 3.7.0Outdated
A fully-featured caching GraphQL client.
html-parse-stringify 3.0.1
Parses well-formed HTML (meaning all tags closed) into an AST and back. quickly.
exenv 1.2.1 - 1.2.2
React's ExecutionEnvironment module extracted for use in other packages & components
@datadog/browser-core 3.10.1 - 3.11.0Outdated
Datadog browser core utilities.
datadog
datadog
react-side-effect 2.1.0Outdated
Create components whose prop changes map to a global side effect
react-helmet 6.1.0
A document head manager for React
react-intersection-observer 8.33.0 - 9.4.1Outdated
Monitor if a component is inside the viewport, using IntersectionObserver API
react-use 9.6.0 - 15.3.8Outdated
Collection of React Hooks
streamich
streamich
xstate 4.7.0 - 4.35.2Outdated
Finite State Machines and Statecharts for the Modern Web.
intersection-observer x.x.x
A polyfill for IntersectionObserver
@datadog/browser-rum-core 3.11.0Outdated
Datadog browser RUM core utilities.
datadog
datadog
react-modal 3.15.1Outdated
Accessible modal dialog component for React.JS
@xobotyi/scrollbar-width 1.9.1 - 1.9.5
A tool to get browser's scrollbars width.
apollo-utilities 1.3.4
Utilities for working with GraphQL ASTs
+1
apollo-bot
benjamn
jbaxleyiii
apollo-link 1.2.12 - 1.2.14
Flexible, lightweight transport layer for GraphQL
jbaxleyiii
peggyrayzis
apollo-bot
@material-ui/core 1.0.0 - 4.12.4
React components that implement Google's Material Design.
ulid 2.3.0
A universally-unique, lexicographically-sortable, identifier generator
alizain
alizain
@reach/utils 0.16.0Outdated
Internal, shared utilities for Reach UI.
+1
ryanflorence
mjackson
chancestrickland
body-scroll-lock 3.1.4 - 3.1.5Outdated
Enables body scroll locking (for iOS Mobile and Tablet, Android, desktop Safari/Chrome/Firefox) without breaking scrolling of a target element (eg. modal/lightbox/flyouts/nav-menus)
react-hot-loader 4.12.16 - 4.13.0Outdated
Tweak React components in real time.
@bugsnag/js 5.0.0 - 7.18.0Outdated
Universal Javascript error reporting. Automatically detect JavaScript errors in the browser and Node.js, with plugins for React, Vue, Angular, Express, Restify and Koa.
@bugsnag/browser 7.18.0Outdated
Bugsnag error reporter for browser JavaScript
+6
joshedney
ahmed_bugsnag
gingerbenw
@chakra-ui/theme 2.1.0 - 2.1.3Outdated
The default theme for chakra components
smoothscroll-polyfill 0.4.4
Smooth Scroll behavior polyfill
sweetalert2 6.2.5 - 7.8.3Outdated
A beautiful, responsive, customizable and accessible (WAI-ARIA) replacement for JavaScript's popup boxes, supported fork of sweetalert
@reach/portal 0.16.2Outdated
Declarative portals for React
+1
ryanflorence
mjackson
chancestrickland
@reach/observe-rect 1.2.0
Observe the Rect of a DOM element.
+1
blainekasten
chancestrickland
mjackson
@reach/auto-id 0.16.0Outdated
Autogenerate IDs to facilitate WAI-ARIA and server rendering.
+1
ryanflorence
mjackson
chancestrickland
@reach/rect 0.16.0 - 0.17.0Outdated
Measure React elements position in the DOM
+1
ryanflorence
mjackson
chancestrickland
@reach/descendants 0.16.1Outdated
A descendant index solution for better accessibility support in compound components
+1
ryanflorence
mjackson
chancestrickland
@reach/popover 0.15.2 - 0.16.2Outdated
Render a portal positioned relative to another element.
+1
ryanflorence
mjackson
chancestrickland
wicg-inert 3.1.2
A polyfill for the proposed inert API
deepcopy 2.0.0 - 2.1.0
deep copy data
sasaplus1
sasaplus1
react-move 6.5.0
Beautiful, data-driven animations for React.
nuka-carousel 4.8.4Outdated
Pure React Carousel
@reach/combobox 0.16.5Outdated
Accessible React Combobox (Autocomplete).
+1
ryanflorence
mjackson
chancestrickland
browser-cookies 1.2.0
Tiny cookies library for the browser
kapellmeister 3.0.1
Orchestration For Animated Transitions
babel-plugin-react-css-modules 5.2.5 - 5.2.6
Transforms styleName to className using compile time CSS module resolution.
tti-polyfill 0.2.2
Polyfill for Time to Interactive. See https://goo.gl/OSmrPk
philipwalton
philipwalton
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
airnan
airnan
broadcast-channel x.x.x
@stitch-fix/i18n x.x.x
@stitch-fix/client-analytics-reporter x.x.x
remove-trailing-slash x.x.x
@stitch-fix/mode-react x.x.x
@stitch-fix/log-weasel x.x.x
@datadog/browser-rum-slim x.x.x
@stitch-fix/knit x.x.x
@mobily/ts-belt x.x.x
@react-hookz/web x.x.x
oblivious-set x.x.x
ts-case-convert x.x.x
@stitch-fix/graphql-api-provider x.x.x
@stitch-fix/event-reporter x.x.x
@stitch-fix/mode-style-system x.x.x
@stitch-fix/kufak-gtm-client x.x.x