zhihu.com 67 packages

Last scanned on Oct 27 at 07:05 PM
url-parse 1.5.3VulnerableOutdated
Small footprint URL parser that works seamlessly across Node.js and browser environments
License
MIT
Footprint
4 KB
Vulnerabilities
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
Affected versions >=0 <1.5.9
Authorization bypass in url-parse
Affected versions >=0 <1.5.6
Authorization Bypass Through User-Controlled Key in url-parse
Affected versions >=0 <1.5.8
url-parse Incorrectly parses URLs that include an '@'
Affected versions >=0 <1.5.7
Matched Modules
Version distribution in production
206
1.5.10
167
1.5.9
50
1.5.3
47
1.4.6
47
1.4.7
24
1.5.4
lodash 4.17.16VulnerableOutdated
Lodash modular utilities.
jws 0.2.0 - 0.2.4VulnerableOutdated
Implementation of JSON Web Signatures
next-auth 4.0.1 - 4.15.0VulnerableOutdated
Authentication for Next.js
next 9.0.6 - 13.0.0VulnerableOutdated
The React Framework
rauchg
timneutkens
vercel-release-bot
tslib 1.2.0 - 2.4.0Outdated
Runtime library for TypeScript helper functions
uuid 7.0.0 - 8.0.0Outdated
RFC4122 (v1, v4, and v5) UUIDs
isarray 1.0.0 - 2.0.5
Array#isArray for older browsers
is-fullwidth-code-point 1.0.0Outdated
Check if the character represented by a given Unicode code point is fullwidth
buffer 4.6.0 - 4.9.2Outdated
Node.js Buffer API, for the browser
@babel/runtime 7.18.2 - 7.20.0Outdated
babel's modular runtime helpers
+1
hzoo
existentialism
nicolo-ribaudo
rxjs 6.5.0 - 6.6.7Outdated
Reactive Extensions for modern JavaScript
base64-js 1.3.0 - 1.5.1
Base64 encoding/decoding in pure JS
events 3.0.0 - 3.3.0
Node's event emitter for all engines.
eventemitter3 2.0.0 - 4.0.7Outdated
EventEmitter3 focuses on performance while maintaining a Node.js AND browser compatible interface.
requires-port 1.0.0
Check if a protocol requires a certain port number to be added to an URL.
prop-types 15.8.0 - 15.8.1
Runtime type checking for React props and similar objects.
react 17.0.0 - 18.2.0
React is a JavaScript library for building user interfaces.
querystringify 2.2.0
Querystringify - Small, simple but powerful query string parser.
url 0.11.0Outdated
The core `url` packaged standalone for use with Browserify.
date-fns 2.29.3Outdated
Modern JavaScript date utility library
kossnocorp
kossnocorp
classnames 2.3.0 - 2.3.1Outdated
A simple utility for conditionally joining classNames together
@emotion/is-prop-valid 0.8.8Outdated
A function to check whether a prop is valid for HTML and SVG elements
+1
emmatown
tkh44
emotion-release-bot
graphql 15.0.0 - 15.8.0Outdated
A Query Language and Runtime which can target any service.
snapdragon-util 2.1.0 - 2.1.1Outdated
Utilities for the snapdragon parser/compiler.
@emotion/serialize 0.11.12 - 0.11.16Outdated
serialization utils for emotion
+1
emmatown
tkh44
emotion-release-bot
@emotion/utils 0.0.4 - 0.11.3Outdated
internal utils for emotion
+1
emmatown
tkh44
emotion-release-bot
@emotion/sheet 0.9.1 - 0.9.4Outdated
emotion's stylesheet
+1
emmatown
tkh44
emotion-release-bot
react-router 3.0.0 - 3.2.6Outdated
Declarative routing for React
is-promise 2.1.0 - 4.0.0
Test whether an object looks like a promises-a+ promise
forbeslindesay
then-bot
@emotion/weak-memoize 0.1.1 - 0.3.0Outdated
A memoization function that uses a WeakMap
+1
emmatown
tkh44
emotion-release-bot
lodash-es 4.17.21
Lodash exported as ES modules.
react-fast-compare 3.1.0 - 3.2.0Outdated
Fastest deep equal comparison for React. Great for React.memo & shouldComponentUpdate. Also really fast general-purpose deep comparison.
crypto-browserify 0.0.0 - 2.0.0Outdated
implementation of crypto for the browser
+2
dcousens
ljharb
cwmma
js-cookie 3.0.1Outdated
A simple, lightweight JavaScript API for handling cookies
querystring-es3 0.2.1
Node's querystring module for all engines. (ES3 compat fork)
reselect 3.0.0 - 3.0.1Outdated
Selectors for Redux.
shallowequal 1.0.1 - 1.1.0
Like lodash isEqualWith but for shallow equal.
raf 3.0.0 - 3.1.0Outdated
requestAnimationFrame polyfill for node and the browser
throttleit 1.0.0Outdated
Throttle a function to limit its execution rate
redux-thunk 2.1.0 - 2.4.1Outdated
Thunk middleware for Redux.
framer-motion 5.0.0 - 6.1.0Outdated
A simple and powerful JavaScript animation library
tabbable 3.1.1 - 3.1.2Outdated
Returns an array of all tabbable DOM nodes within a containing node.
davidtheclark
stefcameron
uncontrollable 3.0.0 - 7.2.1Outdated
Wrap a controlled react component, to allow specific prop/handler pairs to be uncontrolled
@emotion/core 10.0.17 - 10.3.1Outdated
+1
emmatown
tkh44
emotion-release-bot
framesync 4.1.0 - 6.1.2
A frame-synced render loop for JavaScript
popmotion
popmotion
swr 0.2.3 - 0.5.7Outdated
React Hooks library for remote data fetching
react-use 7.3.0 - 17.4.0Outdated
Collection of React Hooks
streamich
streamich
react-beautiful-dnd 1.0.0 - 6.0.2Outdated
Beautiful and accessible drag and drop for lists with React
react-intl 1.1.0 - 1.2.2Outdated
Internationalize React apps. This library provides React components and an API to format dates, numbers, and strings, including pluralization and handling translations.
popmotion 7.3.1 - 11.0.5
The animator's toolbox
style-value-types 1.0.0 - 5.1.2
Parsers, transformers and tests for special value types, eg: %, hex codes etc.
antd 3.11.3Outdated
An enterprise-class UI design language and React components implementation
@emotion/styled-base 10.0.0 - 10.3.0Outdated
Deprecated package which became `@emotion/styled/base`
+1
emmatown
tkh44
emotion-release-bot
@reach/utils 0.10.1 - 0.14.0Outdated
Internal, shared utilities for Reach UI.
+1
ryanflorence
mjackson
chancestrickland
styled-system 3.1.0 - 3.1.2Outdated
Responsive, theme-based style props for building design systems with React
react-dates 14.1.0 - 21.8.0
A responsive and accessible date range picker component built with React
+4
lencioni
ljharb
ahuth
react-native-web 0.0.72 - 0.0.74Outdated
React Native for Web
normalizr 3.5.0 - 3.6.2
Normalizes and denormalizes JSON according to schema for Redux and Flux applications
@styled-system/should-forward-prop 5.0.7 - 5.1.5
Utility for filtering Styled System props with Emotion's shouldForwardProp option
jxnblk
jxnblk
subscribe-ui-event 2.0.0 - 2.0.7
A single, throttle built-in solution to subscribe to browser UI Events.
browser-cookies 1.0.0 - 1.0.2Outdated
Tiny cookies library for the browser
@tannin/plural-forms 1.0.0 - 1.1.0
Compiles a function to compute the plural forms index for a given value
aduth
aduth
@theme-ui/components 0.2.45 - 0.13.1Outdated
Primitive layout, typographic, and other components for use with Theme UI.
+1
jxnblk
johno
hasparus
@theme-ui/color-modes 0.11.0 - 0.15.3Outdated
Adds support for user-controlled color modes
+1
jxnblk
johno
hasparus
lottie-api 1.0.0 - 1.0.2Outdated
A library to edit lottie-web animations dynamically
airnan
airnan
botframework-webchat 0.11.2 - 0.15.0Outdated
A highly-customizable web-based chat client for Azure Bot Services.
+5
botframework
sgellock
cwhitten