lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
6 KB
Command Injection in lodash
Affected versions >=0 <4.17.21
Regular Expression Denial of Service (ReDoS) in lodash
Affected versions >=0 <4.17.21
Prototype Pollution in lodash
Affected versions >=3.7.0 <4.17.19
Matched Modules
Version distribution in production
3 846
axios 0.17.1 - 0.18.0VulnerableOutdated
Promise based HTTP client for the browser and node.js
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
react-is 17.0.0 - 17.0.2Outdated
Brand checking of React Elements.
qs 6.5.2Outdated
A querystring parser that supports nesting and arrays, with a depth limit
@babel/runtime 7.20.5 - 7.20.7Outdated
babel's modular runtime helpers
get-intrinsic 1.1.0 - 1.1.1Outdated
Get and robustly cache all JS language-level intrinsics at first require time
function-bind 1.1.0 - 1.1.1Outdated
Implementation of Function.prototype.bind
path-to-regexp 1.7.0 - 1.8.0Outdated
Express style path to RegExp utility
call-bind 1.0.2Outdated
Robustly `.call.bind()` a function
object-inspect 1.8.0Outdated
string representations of objects in node and the browser
has-symbols 1.0.0 - 1.0.1Outdated
Determine if the JS environment has Symbol support. Supports spec, or shams.
yaml 1.0.0 - 2.2.1Outdated
JavaScript parser and stringifier for YAML
es-abstract 1.18.0 - 1.18.6Outdated
ECMAScript spec abstract operations.
fast-json-stable-stringify 2.0.0 - 2.1.0
deterministic `JSON.stringify()` - a faster version of substack's json-stable-strigify without jsonify
define-properties 1.1.3 - 1.1.4Outdated
Define multiple non-enumerable properties at once. Uses `Object.defineProperty` when available; falls back to standard assignment in older engines.
is-callable 1.1.4 - 1.1.5Outdated
Is this JS value callable? Works with Functions and GeneratorFunctions, despite ES6 @@toStringTag.
domhandler 4.2.0Outdated
Handler for htmlparser2 that turns pages into a dom
object.assign 4.0.4 - 4.1.0Outdated
ES6 spec-compliant Object.assign shim. From https://github.com/es-shims/es6-shim
is-buffer 1.1.4 - 1.1.6Outdated
Determine if an object is a Buffer
object-keys 1.1.0 - 1.1.1
An Object.keys replacement, in case Object.keys is not available. From https://github.com/es-shims/es5-shim
deepmerge 4.2.2Outdated
A library for deep (recursive) merging of Javascript objects
domelementtype 2.2.0 - 2.3.0
all the types of nodes in htmlparser2's dom
core-js 3.15.0 - 3.15.2Outdated
Standard library
is-regex 1.0.4 - 1.0.5Outdated
Is this value a JS regex? Works cross-realm/iframe, and despite ES6 @@toStringTag
is-date-object 1.0.1 - 1.0.3Outdated
Is this value a JS Date object? This module works cross-realm/iframe, and despite ES6 @@toStringTag.
is-negative-zero 2.0.0 - 2.0.2Outdated
Is this value negative zero? === will lie to you
es-to-primitive 1.2.0 - 1.2.1
ECMAScript “ToPrimitive” algorithm. Provides ES5 and ES2015 versions.
function.prototype.name 1.0.3 - 1.1.0Outdated
An ES2015 spec-compliant `Function.prototype.name` shim
object.values 1.0.0 - 1.1.6Outdated
ES2017 spec-compliant Object.values shim.
extend 3.0.2
Port of jQuery.extend for node.js and the browser
scheduler 0.15.0 - 0.23.0Outdated
Cooperative scheduler for the browser environment.
has 1.0.1 - 1.0.3Outdated
Object.prototype.hasOwnProperty.call shortcut
array.prototype.flat 1.2.1Outdated
An ES2019 spec-compliant `Array.prototype.flat` shim/polyfill/replacement that works as far down as ES3.
prop-types 15.7.0 - 15.7.2Outdated
Runtime type checking for React props and similar objects.
react 0.13.0 - 18.2.0Outdated
React is a JavaScript library for building user interfaces.
json-stringify-safe 5.0.1
Like JSON.stringify, but doesn't blow up on circular refs.
lodash.debounce 4.0.8
The lodash method `_.debounce` exported as a module.
performance-now 0.1.3 - 2.1.0
Implements performance.now (based on process.hrtime).
object-is 1.0.1 - 1.1.5Outdated
ES2015-compliant shim for Object.is - differentiates between -0 and +0
hoist-non-react-statics 3.3.1 - 3.3.2
Copies non-react specific statics from a child component to a parent component
classnames 2.2.6Outdated
A simple utility for conditionally joining classNames together
react-transition-group 2.4.0 - 3.0.0Outdated
A react component toolset for managing animations
dom-helpers 5.0.1 - 5.2.1
tiny modular DOM lib for ie9+
tiny-invariant 0.0.2 - 1.3.1Outdated
A tiny invariant function
memoize-one 5.1.0 - 5.1.1Outdated
A memoization library which only remembers the latest invocation
react-router 5.1.1 - 5.3.4Outdated
Declarative routing for React
lodash-es 4.17.21
Lodash exported as ES modules.
react-router-dom 5.1.0 - 5.3.4Outdated
Declarative routing for React web applications
react-fast-compare 2.0.4Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
pluralize 7.0.0Outdated
Pluralize and singularize any word
@storybook/router 5.0.0 - 5.2.8Outdated
Core Storybook Router
react-redux 7.1.0 - 7.2.9Outdated
Official React bindings for Redux
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
history 4.0.0 - 4.10.1Outdated
Manage session history with JavaScript
style-to-object 0.2.3 - 0.4.1Outdated
Parse CSS inline style to JavaScript object.
raf 1.0.0 - 3.4.1
requestAnimationFrame polyfill for node and the browser
polished 3.0.0 - 3.4.4Outdated
A lightweight toolset for writing styles in Javascript.
react-lifecycles-compat 3.0.4
Backwards compatibility polyfill for React class components
inline-style-parser 0.1.0 - 0.1.1Outdated
An inline style parser.
react-remove-scroll 2.2.0 - 2.3.0Outdated
Disables scroll outside of `children` node.
resize-observer-polyfill 1.5.0 - 1.5.1
A polyfill for the Resize Observer API
mitt 1.1.3 - 1.2.0Outdated
Tiny 200b functional Event Emitter / pubsub.
use-callback-ref 1.2.0 - 1.2.1Outdated
The same useRef, but with callback
use-sidecar 1.0.0 - 1.1.2
Sidecar code splitting utils
react-remove-scroll-bar 2.0.0 - 2.1.1Outdated
Removes body scroll without content _shake_
libphonenumber-js 1.9.49Outdated
A simpler (and smaller) rewrite of Google Android's libphonenumber library in javascript
aria-hidden 1.1.1Outdated
Cast aria-hidden to everything, except...
react-style-singleton 2.0.0 - 2.1.1Outdated
Just create a single stylesheet...
lodash.throttle 4.1.1
The lodash method `_.throttle` exported as a module.
react-popper 1.3.3 - 1.3.4Outdated
Official library to use Popper on React projects
popper.js 1.12.6 - 1.16.1
A kickass library to manage your poppers
hyphenate-style-name 1.0.3 - 1.0.4
Hyphenates a camelcased CSS property name
resolve-pathname 2.1.0 - 2.2.0Outdated
Resolve URL pathnames using JavaScript
value-equal 0.2.1 - 0.3.0Outdated
Are these two JavaScript values equal?
tabbable 1.1.2Outdated
Returns an array of all tabbable DOM nodes within a containing node.
@angular/core 8.1.1 - 15.1.1Outdated
Angular - the core framework
react-scripts 0.4.2Outdated
Configuration and scripts for Create React App.
focus-lock 0.6.2 - 0.6.6Outdated
DOM trap for a focus
react-datepicker 0.59.0Outdated
A simple and reusable datepicker component for React
shallow-equal 1.1.0 - 1.2.1Outdated
Typescript-compatible minimalistic shallow equality check for arrays/objects
dijkstrajs 1.0.1 - 1.0.2Outdated
A simple JavaScript implementation of Dijkstra's single-source shortest-paths algorithm.
react-focus-lock 2.4.0 - 2.9.2Outdated
It is a trap! (for a focus)
qrcode 1.5.0Outdated
QRCode / 2d Barcode api with both server side and client side support using canvas
enzyme-shallow-equal 1.0.4Outdated
Adaptation of react-addons-shallow-compare, for independent usage
raf-schd 2.1.1 - 3.0.1Outdated
A scheduler based on requestAnimationFrame
gud 1.0.0
Create a 'gud nuff' (not cryptographically secure) globally unique id
react-intersection-observer 8.29.0 - 8.32.2Outdated
Monitor if a component is inside the viewport, using IntersectionObserver API
mini-create-react-context 0.3.2Outdated
Smaller Polyfill for the proposed React context API
react-helmet-async 0.2.0Outdated
Thread-safe Helmet for React 16+ and friends
xstate 4.7.0 - 4.35.2Outdated
Finite State Machines and Statecharts for the Modern Web.
@stripe/stripe-js 1.9.0 - 1.46.0Outdated
Stripe.js loading utility
@fortawesome/fontawesome-svg-core 1.2.9 - 1.2.27Outdated
The iconic font, CSS, and SVG framework
airbnb-prop-types 2.16.0
Custom React PropType validators that we use at Airbnb.
@fortawesome/free-solid-svg-icons 5.7.0 - 5.15.4Outdated
The iconic font, CSS, and SVG framework
react-query 0.0.11 - 0.0.15Outdated
Hooks for managing, caching and syncing asynchronous and remote data in React
html-react-parser 1.4.5 - 3.0.6Outdated
HTML to React parser.
@material-ui/core 1.0.0 - 4.12.4
React components that implement Google's Material Design.
mobx 5.0.0 - 6.7.0Outdated
Simple, scalable state management.
react-property 2.0.0Outdated
HTML and SVG DOM property configs used by React.
rc-select 8.6.2 - 9.2.3Outdated
React Select
style-to-js 1.1.1 - 1.1.3Outdated
Parses CSS inline style to JavaScript object (camelCased).
mobx-react-lite 1.4.0 - 1.5.2Outdated
Lightweight React bindings for MobX based on React 16.8+ and Hooks
@fortawesome/react-fontawesome 0.1.0 - 0.1.3Outdated
Official React component for Font Awesome 5
mapbox-gl 0.22.0 - 0.33.1Outdated
A WebGL interactive maps library
@reach/utils 0.7.3 - 0.8.0Outdated
Internal, shared utilities for Reach UI.
consolidated-events 1.0.0 - 1.1.1Outdated
Manage multiple event handlers using few event listeners
@fortawesome/free-regular-svg-icons 5.2.0 - 5.15.4Outdated
The iconic font, CSS, and SVG framework
react-portal 4.1.1 - 4.2.2
To make your life with React Portals easier.
@chakra-ui/theme 2.1.0 - 2.1.3Outdated
The default theme for chakra components
react-phone-number-input 3.1.28 - 3.1.52Outdated
Telephone number input React component
@fortawesome/free-brands-svg-icons 5.8.2 - 5.15.4Outdated
The iconic font, CSS, and SVG framework
input-format 0.3.0 - 0.3.7Outdated
Formatting user's text input on-the-fly
document.contains 1.0.2
Polyfill/shim for `document.contains`
react-outside-click-handler 1.3.0
A React component for dealing with clicks outside its subtree
react-with-direction 1.0.0 - 1.4.0
Components to provide and consume RTL or LTR direction in React
react-with-styles 4.1.0Outdated
[![Build Status][travis-svg]][travis-url] [![dependency status][deps-svg]][deps-url] [![dev dependency status][dev-deps-svg]][dev-deps-url] [![License][license-image]][license-url] [![Downloads][downloads-image]][downloads-url]
react-moment-proptypes 1.6.0 - 1.8.1
React proptype for moment module
@react-hook/latest 1.0.3
A React hook that updates useRef().current with the most recent value each invocation
reactstrap 8.0.0 - 8.10.1Outdated
React Bootstrap components
react-scroll 1.7.16Outdated
A scroll component for React.js
react-dates 21.8.0
A responsive and accessible date range picker component built with React
global-cache 1.1.0 - 1.2.1
Sometimes you have to do horrible things, like use the global object to share a singleton. Abstract that away, with this!
react-native-web 0.13.13 - 0.18.4Outdated
React Native for Web
react-with-styles-interface-css 6.0.0
Interface for react-with-styles outputting CSS
@loadable/component 5.15.0 - 5.15.2Outdated
React code splitting made easy.
redux-form 8.2.5 - 8.3.9Outdated
A higher order component decorator for forms using Redux and React
react-autosuggest 10.0.1 - 10.1.0
WAI-ARIA compliant React autosuggest component
section-iterator 2.0.0
Simple iterator for flat and multi section lists
bootstrap-vue 2.0.0 - 2.15.0Outdated
With more than 85 components, over 45 available plugins, several directives, and 1000+ icons, BootstrapVue provides one of the most comprehensive implementations of the Bootstrap v4 component and grid system available for Vue.js v2.6, complete with extens
semantic-ui-react 0.80.0 - 1.1.0Outdated
The official Semantic-UI-React integration.
@splitsoftware/splitio 10.9.0 - 10.17.3Outdated
Split SDK
@react-hook/event 1.0.0 - 1.0.3Outdated
A React hook for managing event listeners, e.g. removing events when a component unmounts.
nuka-carousel 5.2.0Outdated
Pure React Carousel
scroll-behavior 0.9.7 - 0.11.0
Pluggable browser scroll management
aphrodite 0.1.0 - 1.1.0Outdated
Framework-agnostic CSS-in-JS with support for server-side rendering, browser prefixing, and minimum CSS generation
@hcaptcha/react-hcaptcha 1.2.0 - 1.3.1Outdated
A React library for hCaptcha
glamor 2.20.39 - 2.20.40
inline css for component systems
@tannin/plural-forms 1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
react-images 1.0.0 - 1.1.7Outdated
A mobile-friendly, highly customizable, carousel component for displaying media in ReactJS
prebid.js 1.38.0 - 7.32.0Outdated
Header Bidding Management Library
tg-core-redux 0.0.2 - 0.0.4Outdated
@team-griffin/redux-page-loader 0.0.1 - 0.0.4Outdated
```sh npm install --save @team-griffin/redux-page-loader ```