Top npm packages
Vulnerability status for the most-downloaded npm packages, refreshed by the top-1000 sweep job.
| Rank | Package | Latest | Peak affected | Status | Last advisory | History | Severity | |
|---|---|---|---|---|---|---|---|---|
| #1 | semver | 7.8.5 | - | Clear | Jun 21, 2023 | 2 |
2
high
|
|
|
AI-generated context
The semver package has a history of two high-severity Regular Expression Denial of Service (ReDoS) vulnerabilities (GHSA-x6fg-f45m-jf5q and GHSA-c2qf-rxjj-qqgw), meaning malicious input could cause excessive backtracking in regex processing and degrade performance. Both were conventional vulnerabilities with no malware involvement. The current release is clear, so developers using the latest version are not exposed to these issues. Advisory history (2)
|
||||||||
| #2 | minimatch | 10.2.6 | - | Clear | Feb 26, 2026 | 5 |
5
high
|
|
|
AI-generated context
The minimatch package has an exclusively conventional vulnerability history, with all five advisories centered on Regular Expression Denial of Service (ReDoS) flaws — including GHSA-hxm2-r34f-qmc5 dating back to 2018 and more recent issues such as GHSA-23c5-xmqv-rm74 and GHSA-7r86-cg39-jmmj involving catastrophic backtracking from nested extglobs and multiple GLOBSTAR segments. No malware has ever been associated with the package. The current release is clear, so developers depending on minimatch today should simply ensure they are on the latest version to benefit from the fixes to these historical issues. Advisory history (5)
|
||||||||
| #3 | debug | 4.4.3 | 4.4.2 | Clear | Sep 15, 2025 Malware incident · Sep 2025 | 4 |
2
high
1
low
1
malware
|
|
|
AI-generated context
The `debug` package has a notable history that includes two ReDoS (Regular Expression Denial of Service) vulnerabilities across older versions (GHSA-gxpj-cx7g-858c and GHSA-9vvw-cc9w-f27h), as well as a serious incident in which version 4.4.2 was compromised via an npm account takeover and contained malicious code (MAL-2025-46974). The malicious version has since been addressed, and the current release, 4.4.3, is clear. Advisory history (4)
|
||||||||
| #4 | ansi-styles | 7.0.0 | 6.2.2 | Clear | Sep 08, 2025 Malware incident · Sep 2025 | 1 |
1
malware
|
|
|
AI-generated context
Advisory MAL-2025-46967 flagged a malicious version of ansi-styles on npm, indicating that a compromised release was published at some point in the package's history. This was a malware incident rather than a conventional vulnerability in the package's own code. The current latest release, version 6.2.3, is clear, so developers depending on that version are not affected by this historical incident. Advisory history (1)
|
||||||||
| #5 | brace-expansion | 5.0.8 | 4.0.0 | Clear | Jul 24, 2026 | 6 |
3
high
2
moderate
1
low
|
|
|
Advisory history (6)
|
||||||||
| #6 | strip-ansi | 7.2.0 | 7.1.1 | Clear | Sep 08, 2025 Malware incident · Sep 2025 | 1 |
1
malware
|
|
|
AI-generated context
Advisory MAL-2025-46980 flagged a malicious version of strip-ansi on npm, marking the only advisory in this package's history as a malware incident rather than a conventional vulnerability. The current release, version 7.2.0, has since been cleared, meaning the malicious code is no longer present in the latest published version. Developers depending on this package should ensure they are pinned to the latest clean release and not inadvertently pulling in the compromised version. Advisory history (1)
|
||||||||
| #7 | ansi-regex | 6.2.2 | 6.2.1 | Clear | Sep 08, 2025 Malware incident · Sep 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
The package has two historical advisories: GHSA-93q8-gq69-wqmw, a high-severity vulnerability involving inefficient regular expression complexity that could be exploited for denial-of-service attacks, and MAL-2025-46966, which flagged malicious code in a version of the package on npm. The current release, 6.2.2, is clear of both issues, but the malware incident in particular is worth noting as part of the package's history when assessing supply chain risk. Advisory history (2)
|
||||||||
| #8 | ms | 2.1.3 | - | Clear | Jan 05, 2023 | 2 |
1
high
1
moderate
|
|
|
AI-generated context
The `ms` package has two historical advisories, both related to Regular Expression Denial of Service (ReDoS) vulnerabilities (GHSA-3fx5-fwvr-xrjg and GHSA-w9mr-4mfr-499f), where inefficient regular expression complexity could be exploited to cause performance degradation. These were conventional security issues, not malware, and both have since been addressed. The current release (2.1.3) is clear, so developers depending on an up-to-date version of this package are not affected by either of these past vulnerabilities. Advisory history (2)
|
||||||||
| #9 | supports-color | 11.0.0 | 10.2.1 | Clear | Sep 08, 2025 Malware incident · Sep 2025 | 1 |
1
malware
|
|
|
AI-generated context
Advisory MAL-2025-46981 flagged a malicious version of the supports-color npm package, indicating that a compromised release containing malware was published at some point in the package's history. The current latest release, version 10.2.2, has since been cleared, so developers depending on that version are not affected by the earlier incident. Advisory history (1)
|
||||||||
| #10 | chalk | 6.0.0 | 5.6.1 | Clear | Sep 08, 2025 Malware incident · Sep 2025 | 1 |
1
malware
|
|
|
AI-generated context
Chalk has one malware advisory in its history, MAL-2025-46969, which identified malicious code published under the chalk package name on npm. This type of incident typically involves a compromised or typosquatted version rather than the legitimate package's entire release history, and the current latest release at version 5.6.2 is clear of any such concerns. Advisory history (1)
|
||||||||
| #11 | commander | 15.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #12 | lru-cache | 11.5.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #13 | string-width | 8.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #14 | wrap-ansi | 10.0.0 | 9.0.1 | Clear | Sep 08, 2025 Malware incident · Sep 2025 | 1 |
1
malware
|
|
|
AI-generated context
Advisory MAL-2025-46983 flagged a malicious version of wrap-ansi on npm, indicating that at some point a compromised release was published to the registry. This was a malware incident rather than a conventional vulnerability in the package's own code. The current latest release, version 10.0.0, is clear, so developers using that version are not affected by this history. Advisory history (1)
|
||||||||
| #15 | tslib | 2.8.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #16 | picomatch | 4.0.5 | - | Clear | Mar 25, 2026 | 2 |
1
high
1
moderate
|
|
|
AI-generated context
Picomatch has two historical security advisories, both conventional vulnerabilities rather than malware: GHSA-3v7f-55p6-f55p identified a method injection issue in POSIX character classes that caused incorrect glob matching, and GHSA-c2c7-rcm5-vvqj flagged a high-severity ReDoS vulnerability via extglob quantifiers. Both issues have been addressed, and the package's current release at version 4.0.5 is clear, meaning developers depending on it today can do so without concern from these past findings. Advisory history (2)
|
||||||||
| #17 | emoji-regex | 10.6.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #18 | glob | 13.0.6 | - | Clear | Nov 17, 2025 | 1 |
1
high
|
|
|
AI-generated context
The `glob` package has one historical advisory (GHSA-5j98-mcp5-4vw2), a high-severity conventional vulnerability in which the CLI's `-c`/`--cmd` flag could allow command injection by executing matched filenames with `shell: true`. This was not a malware issue. The latest release, version 13.0.6, is clear, so developers depending on it today should simply ensure they are on an up-to-date version. Advisory history (1)
|
||||||||
| #19 | type-fest | 5.8.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #20 | color-name | 2.1.1 | 2.0.1 | Clear | Sep 15, 2025 Malware incident · Sep 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
The package color-name has a notable security history: version 2.0.1 was compromised via an npm account takeover that introduced malicious code, documented in both GHSA-5fvm-p68v-5wmh and MAL-2025-46972. This was a supply chain incident involving actual malware rather than a conventional vulnerability. The latest release, 2.1.0, is clear, indicating the maintainers have regained control and resolved the issue. Advisory history (2)
|
||||||||
| #21 | eslint-visitor-keys | 5.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #22 | color-convert | 3.1.3 | 3.1.1 | Clear | Sep 15, 2025 Malware incident · Sep 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
color-convert has a notable security incident in its history: version 3.1.1 was compromised with malicious code following an npm account takeover, as documented in GHSA-pxx3-g568-hxr4 and MAL-2025-46971. This was a supply chain attack involving actual malware injected into a published release, not a conventional vulnerability. The package has since been remediated and the current release (3.1.3) is clear, so developers on the latest version are not affected. Advisory history (2)
|
||||||||
| #23 | ajv | 8.20.0 | - | Clear | Feb 11, 2026 | 2 |
2
moderate
|
|
|
AI-generated context
Ajv has two moderate-severity vulnerability advisories in its history: a prototype pollution issue (GHSA-v88g-cgmw-v5xw) and a ReDoS vulnerability triggered when using the `$data` option (GHSA-2g4f-4pwh-qvx6), both conventional security flaws with no malware involvement. Neither advisory involved supply chain compromise or malicious code. The latest release of ajv is currently clear, so developers depending on an up-to-date version are not affected by these past issues. Advisory history (2)
|
||||||||
| #24 | minipass | 7.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #25 | source-map | 0.8.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #26 | balanced-match | 4.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #27 | readable-stream | 4.7.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #28 | which | 7.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #29 | glob-parent | 6.0.2 | 6.0.0 | Clear | Jul 18, 2022 | 2 |
2
high
|
|
|
AI-generated context
The glob-parent package has two historical high-severity advisories in its past, both involving Regular Expression Denial of Service (ReDoS) vulnerabilities — one in the enclosure regex (GHSA-ww39-953v-wcq6) and one affecting version 6.0.0 specifically (GHSA-cj88-88mr-972w). Neither advisory involved malware; both were conventional algorithmic complexity issues that could allow an attacker to cause excessive processing through crafted input. These vulnerabilities have since been addressed, and the current release (6.0.2) is clear. Advisory history (2)
|
||||||||
| #30 | escape-string-regexp | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #31 | has-flag | 5.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #32 | find-up | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #33 | locate-path | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #34 | json-schema-traverse | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #35 | p-limit | 7.3.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #36 | yallist | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #37 | safe-buffer | 5.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #38 | uuid | 14.0.1 | - | Clear | Apr 22, 2026 | 1 |
1
moderate
|
|
|
AI-generated context
The `uuid` package has one moderate-severity advisory in its history, GHSA-w5hq-g745-h8pq, which described a missing buffer bounds check affecting v3, v5, and v6 UUID generation when a `buf` argument was provided — a conventional vulnerability with no malware involvement. This issue has since been addressed, and the package's current release (14.0.1) is clear. Advisory history (1)
|
||||||||
| #39 | p-locate | 7.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #40 | undici-types | 8.9.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #41 | ignore | 7.0.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #42 | iconv-lite | 0.7.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #43 | signal-exit | 4.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #44 | esbuild | 0.28.1 | - | Clear | Jun 12, 2026 | 2 |
1
moderate
1
low
|
|
|
AI-generated context
Esbuild has two historical vulnerability advisories, both conventional security issues rather than malware. GHSA-67mh-4wv8-2f99 flagged a moderate-severity flaw allowing arbitrary websites to send requests to the development server and read responses, while GHSA-g7r4-m6w7-qqqr identified a low-severity arbitrary file read issue on Windows when running the dev server. Both issues have since been addressed, and the package's current release at version 0.28.1 is clear. Advisory history (2)
|
||||||||
| #45 | is-fullwidth-code-point | 5.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #46 | js-yaml | 5.2.2 | - | Clear | Jul 24, 2026 | 9 |
1
critical
3
high
5
moderate
|
|
|
Advisory history (9)
|
||||||||
| #47 | entities | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #48 | globals | 17.8.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #49 | postcss | 8.5.24 | - | Clear | Jul 24, 2026 | 6 |
2
high
4
moderate
|
|
|
Advisory history (6)
|
||||||||
| #50 | isexe | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #51 | isarray | 2.0.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #52 | path-key | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #53 | string_decoder | 1.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #54 | argparse | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #55 | ws | 8.21.1 | - | Clear | Jun 15, 2026 | 7 |
4
high
2
moderate
1
low
|
|
|
AI-generated context
The `ws` package has a history of conventional security vulnerabilities — no malware — spanning memory disclosure issues (GHSA-2mhh-w6q8-5hxw, GHSA-58qx-3vcg-4xpx), multiple denial-of-service vulnerabilities including those triggered by large messages, excessive HTTP headers, and memory exhaustion from fragmented data (GHSA-6663-c963-2gqg, GHSA-5v72-xg48-5rpm, GHSA-3h5v-q93c-6h6q, GHSA-96hv-2xvq-fx4p), and a ReDoS in a WebSocket protocol header (GHSA-6fc8-4gx4-v693). These vulnerabilities were addressed in successive releases over the years, and the current version 8.21.1 is clear. Developers depending on `ws` should ensure they are running the latest version to benefit from all historical fixes. Advisory history (7)
|
||||||||
| #56 | mime-db | 1.54.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #57 | resolve | 1.22.12 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #58 | agent-base | 9.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #59 | @esbuild/linux-x64 | 0.28.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #60 | yargs-parser | 22.0.0 | - | Clear | Sep 04, 2020 | 1 |
1
moderate
|
|
|
AI-generated context
yargs-parser has one advisory in its history, GHSA-p9pc-299p-vxgp, a moderate-severity prototype pollution vulnerability affecting older versions of the package. This was a conventional security flaw rather than any form of malware, and it has since been resolved. The current release is clear, so developers depending on up-to-date versions of yargs-parser are not affected by this past issue. Advisory history (1)
|
||||||||
| #61 | mime-types | 3.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #62 | acorn | 8.18.0 | - | Clear | Apr 03, 2020 | 1 |
1
high
|
|
|
AI-generated context
Acorn has one advisory in its history, GHSA-6chw-6frg-f759, a high-severity Regular Expression Denial of Service vulnerability published in 2020. This was a conventional vulnerability rather than malware, affecting how the parser handled certain inputs that could cause excessive backtracking. The issue has since been resolved, and the package's current release is clear. Advisory history (1)
|
||||||||
| #63 | estraverse | 5.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #64 | cross-spawn | 7.0.6 | - | Clear | Nov 08, 2024 | 1 |
1
high
|
|
|
AI-generated context
The package has one advisory in its history, GHSA-3xgq-45jj-v275, a high-severity Regular Expression Denial of Service (ReDoS) vulnerability affecting earlier versions of cross-spawn. This was a conventional vulnerability rather than malware, where a crafted input could cause excessive backtracking in a regular expression. The issue has since been addressed, and the current release (7.0.6) is clear. Advisory history (1)
|
||||||||
| #65 | react-is | 19.2.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #66 | picocolors | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #67 | fs-extra | 11.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #68 | hasown | 2.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #69 | nanoid | 6.0.0 | - | Clear | Dec 09, 2024 | 2 |
2
moderate
|
|
|
AI-generated context
Nanoid has two moderate-severity advisories in its history, both involving conventional vulnerabilities rather than malware: GHSA-qrpm-p2h7-hrv2 concerned exposure of sensitive information to unauthorized actors, and GHSA-mwcw-c2x4-8c55 flagged predictable ID generation when non-integer values were passed as input. These issues have been addressed, and the package's current release at version 6.0.0 is clear. Advisory history (2)
|
||||||||
| #70 | yargs | 18.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #71 | resolve-from | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #72 | shebang-command | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #73 | pretty-format | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #74 | json5 | 2.2.3 | - | Clear | Dec 29, 2022 | 1 |
1
high
|
|
|
AI-generated context
The json5 package has one historical high-severity advisory (GHSA-9c47-m6qq-7p4h) involving a Prototype Pollution vulnerability in its parse method, which could allow attackers to manipulate JavaScript object prototypes. This was a conventional vulnerability, not malware. The package has since been patched and its latest release is clear. Advisory history (1)
|
||||||||
| #75 | https-proxy-agent | 9.1.0 | - | Clear | Apr 16, 2020 | 2 |
1
critical
1
moderate
|
|
|
AI-generated context
The `https-proxy-agent` package has two historical vulnerability advisories: a critical Denial of Service issue (GHSA-8g7p-74h8-hg48) and a moderate Machine-In-The-Middle vulnerability (GHSA-pc5p-h8pf-mvwp), both involving conventional security flaws rather than malware. These issues affected older versions of the package and have since been resolved, as the current release at version 9.1.0 is clear of known advisories. Advisory history (2)
|
||||||||
| #76 | path-to-regexp | 8.4.2 | - | Clear | Mar 27, 2026 | 5 |
4
high
1
moderate
|
|
|
AI-generated context
path-to-regexp has an advisory history focused exclusively on conventional Regular Expression Denial of Service (ReDoS) vulnerabilities, with no malware involvement — advisories GHSA-9wv6-86v2-598j, GHSA-rhx6-c78j-4q9w, GHSA-27v5-c462-wpq7, GHSA-37ch-88jc-xwx2, and GHSA-j3q9-mxjg-w52f all describe scenarios where crafted inputs involving backtracking patterns, multiple wildcards, route parameters, or sequential optional groups could cause excessive processing. These issues reflect an ongoing effort to harden the library's regex generation against pathological inputs. The current release at version 8.4.2 is clear, meaning developers on the latest version are not exposed to these historically identified vulnerabilities. Advisory history (5)
|
||||||||
| #77 | path-exists | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #78 | punycode | 2.3.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #79 | js-tokens | 10.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #80 | cliui | 9.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #81 | shebang-regex | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #82 | @babel/types | 8.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #83 | chokidar | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #84 | strip-json-comments | 5.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #85 | inherits | 2.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #86 | webidl-conversions | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #87 | get-stream | 9.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #88 | eslint-scope | 9.1.2 | 3.7.2 | Clear | Jul 12, 2018 | 1 |
1
critical
|
|
|
AI-generated context
In 2018, eslint-scope was the subject of a critical advisory (GHSA-hxxf-q3w9-4xgw) after a malicious actor compromised a published version of the package to include harmful code, making it one of the more notable supply chain incidents in the JavaScript ecosystem at the time. This was a one-time compromise rather than an ongoing vulnerability class, and the issue was identified and addressed by the maintainers. The package's latest release is now clear, so developers depending on a current version of eslint-scope are not at risk from that historical incident. Advisory history (1)
|
||||||||
| #89 | cookie | 2.0.1 | - | Clear | Oct 04, 2024 | 1 |
1
low
|
|
|
AI-generated context
The `cookie` package has one historical advisory in its record, GHSA-pxg6-pf52-xh8x, a low-severity vulnerability in which the package accepted cookie names, paths, and domains containing out-of-bounds characters. This was a conventional vulnerability with no malware involvement, and it has since been resolved. Developers depending on the package today can rely on the current release (2.0.1) being clear of known issues. Advisory history (1)
|
||||||||
| #90 | @babel/parser | 8.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #91 | qs | 6.15.3 | - | Clear | May 22, 2026 | 7 |
4
high
2
moderate
1
low
|
|
|
AI-generated context
The `qs` package has an extensive history of conventional security vulnerabilities — no malware has ever been involved — spanning denial-of-service issues (including memory exhaustion and event loop blocking) and prototype pollution flaws across advisories such as GHSA-jjv7-qpx3-h62q, GHSA-hrpp-h998-j3pp, and several others. These issues reflect recurring challenges in safely parsing query strings, particularly around array handling and object prototype manipulation. The current release (6.15.3) is clear, so developers using the latest version are not exposed to these historical vulnerabilities. Advisory history (7)
|
||||||||
| #92 | is-number | 7.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #93 | whatwg-url | 17.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #94 | @types/estree | 1.0.9 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #95 | tr46 | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #96 | convert-source-map | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #97 | is-glob | 4.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #98 | braces | 3.0.3 | - | Clear | May 14, 2024 | 2 |
1
high
1
low
|
|
|
AI-generated context
The `braces` package has two historical advisories related to Regular Expression Denial of Service and uncontrolled resource consumption (GHSA-cwfw-4gq5-mrqx and GHSA-grv7-fg5c-xmjg), both conventional vulnerabilities rather than malware. These issues, ranging from low to high severity, affected older versions of the package. The current release (3.0.3) is clear, so developers on the latest version are not exposed to these past vulnerabilities. Advisory history (2)
|
||||||||
| #99 | fast-deep-equal | 3.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #100 | form-data | 4.0.6 | - | Clear | Jun 15, 2026 | 2 |
1
critical
1
high
|
|
|
AI-generated context
The `form-data` package has two conventional security vulnerabilities in its history: a critical advisory (GHSA-fjxv-7rqg-78g4) concerning use of an unsafe random function when generating multipart boundaries, and a high-severity advisory (GHSA-hmw2-7cc7-3qxx) involving CRLF injection through unescaped multipart field names and filenames. Neither issue involved malware. The package is currently clear at version 4.0.6, meaning these vulnerabilities have been addressed in the latest release. Advisory history (2)
|
||||||||
| #101 | lodash | 4.18.1 | - | Clear | Apr 01, 2026 | 10 |
1
critical
4
high
5
moderate
|
|
|
AI-generated context
Lodash has an extensive history of conventional security vulnerabilities spanning several years, with no malware involvement. The advisories cover recurring prototype pollution issues (GHSA-fvqr-27wr-82fm, GHSA-4xc9-xhrj-v574, GHSA-jf85-cpcp-j695, GHSA-p6mc-m468-83gw, and others), as well as command injection, code injection via `_.template`, and regular expression denial of service. These are resolved in the current release, but the pattern of repeated vulnerabilities in this package is worth factoring into ongoing dependency management and security monitoring. Advisory history (10)
|
||||||||
| #102 | @babel/helper-validator-identifier | 8.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #103 | electron-to-chromium | 1.5.398 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #104 | fill-range | 7.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #105 | function-bind | 1.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #106 | readdirp | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #107 | escalade | 3.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #108 | graceful-fs | 4.2.11 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #109 | negotiator | 1.0.0 | - | Clear | Oct 09, 2018 | 1 |
1
high
|
|
|
AI-generated context
The `negotiator` package has one historical advisory in its record, GHSA-7mc5-chhp-fmc3, a high-severity Regular Expression Denial of Service vulnerability published in 2018. This was a conventional vulnerability rather than malware, involving a crafted input that could cause excessive backtracking in a regex. The package is currently clear at its latest release, so developers depending on an up-to-date version are not affected by this past issue. Advisory history (1)
|
||||||||
| #110 | is-stream | 4.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #111 | camelcase | 9.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #112 | @babel/runtime | 8.0.0 | - | Clear | Mar 11, 2025 | 1 |
1
moderate
|
|
|
AI-generated context
@babel/runtime has one historical advisory (GHSA-968p-4wvh-cqc8) involving a moderate-severity vulnerability where transpiled code using named capturing groups could produce inefficient regular expressions in `.replace` calls, potentially leading to performance issues. This was a conventional vulnerability with no malware involvement. The package's current release is clear, so developers depending on it today are not affected by this issue. Advisory history (1)
|
||||||||
| #113 | yocto-queue | 1.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #114 | to-regex-range | 5.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #115 | node-fetch | 3.3.2 | - | Clear | Aug 02, 2022 | 3 |
1
high
1
moderate
1
low
|
|
|
AI-generated context
node-fetch has a history of conventional security vulnerabilities — no malware was ever involved. The advisories covered a high-severity issue where secure headers were forwarded to untrusted sites (GHSA-r683-j2x4-v87g), a moderate-severity inefficient regular expression (GHSA-vp56-6g26-6827), and a low-severity bug where the `size` option was ignored after redirects (GHSA-w7rc-rwvf-8q5r). These have all been addressed in the package's history, and the current release at version 3.3.2 is clear. Advisory history (3)
|
||||||||
| #116 | micromatch | 4.0.8 | - | Clear | May 14, 2024 | 1 |
1
moderate
|
|
|
AI-generated context
Micromatch has one advisory in its history, GHSA-952p-6rrq-rcjv, which identified a moderate-severity Regular Expression Denial of Service (ReDoS) vulnerability. This was a conventional vulnerability rather than malware, meaning a crafted input could cause excessive backtracking in the regex engine. The issue has since been addressed, and the current release (4.0.8) is clear. Advisory history (1)
|
||||||||
| #117 | node-releases | 2.0.51 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #118 | get-intrinsic | 1.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #119 | universalify | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #120 | path-scurry | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #121 | jsesc | 3.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #122 | browserslist | 4.28.7 | - | Clear | May 24, 2021 | 1 |
1
moderate
|
|
|
AI-generated context
Browserslist has one advisory in its history, GHSA-w8qv-6jwh-64r5, a moderate-severity Regular Expression Denial of Service vulnerability published in 2021. This was a conventional vulnerability, not malware, where a crafted input could cause excessive backtracking in a regular expression. The issue has since been resolved, and the package's current release is clear. Advisory history (1)
|
||||||||
| #123 | es-errors | 1.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #124 | statuses | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #125 | @radix-ui/react-primitive | 2.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #126 | magic-string | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #127 | rimraf | 6.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #128 | is-extglob | 2.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #129 | @jridgewell/trace-mapping | 0.3.31 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #130 | @jridgewell/resolve-uri | 3.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #131 | http-errors | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #132 | onetime | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #133 | has-symbols | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #134 | es-define-property | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #135 | gopd | 1.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #136 | util-deprecate | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #137 | object-assign | 4.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #138 | jiti | 2.7.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #139 | yaml | 2.9.0 | - | Clear | Mar 25, 2026 | 2 |
1
high
1
moderate
|
|
|
AI-generated context
The `yaml` package has two historical vulnerability advisories: GHSA-f9xv-q969-pqx4, a high-severity uncaught exception issue, and GHSA-48c2-rrv3-qjmp, a moderate-severity stack overflow triggered by deeply nested YAML collections. Both were conventional vulnerabilities rather than malware. The package's latest release is currently clear, so developers on an up-to-date version are not affected by either of these past issues. Advisory history (2)
|
||||||||
| #140 | dotenv | 17.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #141 | @babel/generator | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #142 | @babel/template | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #143 | imurmurhash | 0.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #144 | postcss-selector-parser | 7.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #145 | fast-glob | 3.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #146 | update-browserslist-db | 1.2.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #147 | @types/node | 26.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #148 | @babel/compat-data | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #149 | eventemitter3 | 5.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #150 | callsites | 4.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #151 | http-proxy-agent | 9.1.0 | - | Clear | Jan 06, 2022 | 2 |
1
high
1
moderate
|
|
|
AI-generated context
The http-proxy-agent package has two historical denial-of-service vulnerabilities in its past: a high-severity issue (GHSA-8w57-jfpm-945m) published in 2019 and a moderate-severity resource exhaustion issue (GHSA-86wf-436m-h424) published in 2022, both involving conventional vulnerabilities rather than malware. These have since been addressed, and the package's current release at version 9.1.0 is clear of known advisories. Advisory history (2)
|
||||||||
| #152 | detect-libc | 2.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #153 | espree | 11.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #154 | execa | 10.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #155 | @babel/core | 8.0.1 | - | Clear | Jun 15, 2026 | 1 |
1
low
|
|
|
AI-generated context
@babel/core has one low-severity advisory in its history (GHSA-4x5r-pxfx-6jf8), which described an arbitrary file read vulnerability exploitable via a sourceMappingURL comment. This was a conventional security flaw, not malware, and the package's current release at version 8.0.1 is clear of this issue. Advisory history (1)
|
||||||||
| #156 | @babel/helpers | 8.0.0 | - | Clear | Mar 11, 2025 | 1 |
1
moderate
|
|
|
AI-generated context
The package has one historical advisory (GHSA-968p-4wvh-cqc8) involving a moderate-severity vulnerability where Babel's code generation for named capturing groups produced inefficient regular expressions, creating potential ReDoS exposure. This was a conventional vulnerability, not malware-related. The latest release, version 8.0.0, is clear, so developers can depend on it without concern from that prior issue. Advisory history (1)
|
||||||||
| #157 | concat-map | 0.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #158 | source-map-js | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #159 | tinyglobby | 0.2.17 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #160 | call-bind-apply-helpers | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #161 | flat-cache | 6.1.23 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #162 | fdir | 6.5.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #163 | pify | 6.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #164 | @jest/types | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #165 | normalize-path | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #166 | is-core-module | 2.16.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #167 | eslint | 10.8.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #168 | minimist | 1.2.8 | - | Clear | Mar 18, 2022 | 2 |
1
critical
1
moderate
|
|
|
AI-generated context
The minimist package has two historical advisories, both involving prototype pollution vulnerabilities — one moderate (GHSA-vh95-rmgr-6w4m) and one critical (GHSA-xvch-5gv4-984h) — neither of which involved malware. These were conventional security flaws that have since been addressed, and the package's current release at version 1.2.8 is clear. Advisory history (2)
|
||||||||
| #169 | estree-walker | 3.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #170 | file-entry-cache | 11.1.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #171 | object-inspect | 1.13.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #172 | buffer | 6.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #173 | uri-js | 4.4.1 | - | Clear | Jul 24, 2018 | 1 |
1
moderate
|
|
|
AI-generated context
uri-js has one advisory in its history, GHSA-333w-rxj3-f55r, a moderate-severity Regular Expression Denial of Service vulnerability published in 2018. This was a conventional vulnerability rather than malware, affecting how the package processed certain URI inputs. The package's latest release is clear, so developers depending on the current version are not exposed to this issue. Advisory history (1)
|
||||||||
| #174 | import-fresh | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #175 | @babel/helper-module-transforms | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #176 | optionator | 0.9.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #177 | flatted | 3.4.3 | - | Clear | Mar 19, 2026 | 2 |
2
high
|
|
|
AI-generated context
The flatted package has two high-severity vulnerability advisories in its history: GHSA-25h7-pfq9-p65f, involving an unbounded recursion denial-of-service in the `parse()` revive phase, and GHSA-rf6f-7fwh-wjgh, involving prototype pollution also through `parse()`. Both were conventional vulnerabilities with no malware involved, and the current release (3.4.2) is clear, meaning developers on the latest version are not exposed to these issues. Advisory history (2)
|
||||||||
| #178 | math-intrinsics | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #179 | safer-buffer | 2.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #180 | y18n | 5.0.8 | 4.0.0 | Clear | Mar 29, 2021 | 1 |
1
high
|
|
|
AI-generated context
The y18n package has one historical advisory in its record, GHSA-c4w7-xm78-47vh, a high-severity prototype pollution vulnerability that was disclosed in March 2021. This was a conventional security flaw, not malware, and it has since been addressed. Developers depending on y18n today can do so with confidence, as the latest release is clear of known vulnerabilities. Advisory history (1)
|
||||||||
| #181 | @babel/helper-module-imports | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #182 | mkdirp | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #183 | dunder-proto | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #184 | path-parse | 1.0.7 | - | Clear | Aug 10, 2021 | 1 |
1
moderate
|
|
|
AI-generated context
path-parse has one advisory in its history, GHSA-hj48-42vr-x3v9, a moderate-severity Regular Expression Denial of Service vulnerability affecting older versions. This was a conventional ReDoS issue, not malware. The package has since been updated and its current release at version 1.0.7 is clear of known vulnerabilities. Advisory history (1)
|
||||||||
| #185 | fastq | 1.20.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #186 | levn | 0.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #187 | @babel/helper-compilation-targets | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #188 | @babel/helper-string-parser | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #189 | keyv | 5.6.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #190 | get-proto | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #191 | csstype | 3.2.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #192 | npm-run-path | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #193 | fast-json-stable-stringify | 2.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #194 | reusify | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #195 | @babel/helper-plugin-utils | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #196 | kind-of | 6.0.3 | - | Clear | Mar 31, 2020 | 1 |
1
high
|
|
|
AI-generated context
The `kind-of` package has one historical advisory in its record, GHSA-6c8f-qphg-qjgp, a high-severity vulnerability involving a validation bypass that was published in 2020. This was a conventional security flaw, not malware, and it has since been resolved. The package's latest release (6.0.3) is clear, so developers depending on an up-to-date version are not affected by this past issue. Advisory history (1)
|
||||||||
| #197 | mime | 4.1.0 | - | Clear | Jul 20, 2018 | 1 |
1
high
|
|
|
AI-generated context
The `mime` package has one historical advisory in its record (GHSA-wrvr-8mpx-r7pp), a high-severity Regular Expression Denial of Service vulnerability that could be triggered when performing MIME type lookups on untrusted user input. This was a conventional vulnerability, not malware. The package's current release is clear, so developers depending on an up-to-date version of `mime` are not affected by this past issue. Advisory history (1)
|
||||||||
| #198 | caniuse-lite | 1.0.30001806 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #199 | lines-and-columns | 2.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #200 | fast-levenshtein | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #201 | supports-preserve-symlinks-flag | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #202 | make-dir | 5.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #203 | slash | 5.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #204 | prelude-ls | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #205 | typescript | 7.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #206 | strip-bom | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #207 | parent-module | 3.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #208 | esutils | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #209 | ci-info | 4.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #210 | @smithy/util-utf8 | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #211 | type-check | 0.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #212 | mimic-fn | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #213 | @babel/helper-validator-option | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #214 | @types/json-schema | 7.0.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #215 | @rolldown/pluginutils | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #216 | side-channel-list | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #217 | json-buffer | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #218 | raw-body | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #219 | has-tostringtag | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #220 | wrappy | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #221 | diff | 9.0.0 | - | Clear | Jan 14, 2026 | 2 |
1
high
1
low
|
|
|
AI-generated context
The `diff` package has two historical advisories, both involving denial of service vulnerabilities rather than malware. GHSA-h6ch-v84p-w6p9 (high severity) identified a Regular Expression Denial of Service issue, while GHSA-73rr-hh4g-fpgx (low severity) flagged DoS risks in the `parsePatch` and `applyPatch` functions. The package's latest release (9.0.0) is currently clear, so developers depending on an up-to-date version are not affected by either of these past issues. Advisory history (2)
|
||||||||
| #222 | jackspeak | 4.2.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #223 | baseline-browser-mapping | 2.11.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #224 | deep-is | 0.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #225 | foreground-child | 4.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #226 | @eslint/js | 10.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #227 | anymatch | 3.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #228 | natural-compare | 1.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #229 | esquery | 1.7.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #230 | @eslint-community/regexpp | 4.12.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #231 | es-set-tostringtag | 2.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #232 | acorn-jsx | 5.3.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #233 | parse5 | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #234 | finalhandler | 2.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #235 | parse-json | 8.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #236 | depd | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #237 | axios | 1.18.1 | 1.15.2 | Clear | Jul 20, 2026 Malware incident · Mar 2026 | 44 |
18
high
23
moderate
2
low
1
malware
|
|
|
Advisory history (44)
|
||||||||
| #238 | run-parallel | 1.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #239 | source-map-support | 0.5.21 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #240 | esrecurse | 4.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #241 | call-bound | 1.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #242 | content-disposition | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #243 | human-signals | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #244 | ts-api-utils | 2.5.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #245 | ansi-escapes | 7.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #246 | jest-util | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #247 | send | 1.2.1 | - | Clear | Sep 10, 2024 | 3 |
1
moderate
2
low
|
|
|
AI-generated context
The `send` package has a history of conventional security vulnerabilities, including two low-to-moderate severity issues disclosed in 2017 involving directory traversal and root path disclosure (GHSA-xwg4-93c6-3h42 and GHSA-jgqf-hwc5-hh37), as well as a more recent low-severity template injection flaw that could lead to XSS (GHSA-m6fv-jmcg-4jfg). None of these advisories involved malware. The current release is clear, so developers using the latest version benefit from the fixes that addressed this past vulnerability history. Advisory history (3)
|
||||||||
| #248 | @opentelemetry/core | 2.10.0 | - | Clear | Jun 15, 2026 | 1 |
1
moderate
|
|
|
AI-generated context
The `@opentelemetry/core` package has one historical advisory (GHSA-8988-4f7v-96qf) involving a moderate-severity conventional vulnerability related to unbounded memory allocation in W3C Baggage propagation. This was not malware, but rather a resource-management flaw that could have allowed excessive memory consumption. The issue has since been resolved, and the current release at version 2.9.0 is clear. Advisory history (1)
|
||||||||
| #249 | type-is | 2.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #250 | encodeurl | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #251 | once | 1.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #252 | cosmiconfig | 9.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #253 | lodash.merge | 4.6.2 | - | Clear | Sep 03, 2020 | 2 |
2
high
|
|
|
AI-generated context
The lodash.merge package has two historical high-severity advisories (GHSA-2m96-9w4j-wgv7 and GHSA-h726-x36v-rx45), both concerning prototype pollution vulnerabilities published in September 2020. These were conventional security vulnerabilities, not malware, and no malicious code was ever involved. The package's current release at version 4.6.2 is clear, so developers depending on this version are not exposed to those historical issues. Advisory history (2)
|
||||||||
| #254 | json-stable-stringify-without-jsonify | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #255 | open | 11.0.0 | - | Clear | Jun 20, 2019 | 1 |
1
critical
|
|
|
AI-generated context
The `open` package has one historical advisory in its record, GHSA-28xh-wpgr-7fm8, a critical command injection vulnerability published in 2019. This was a conventional security flaw, not malware, affecting older versions of the package. The issue has since been resolved, and the current release at version 11.0.0 is clear. Advisory history (1)
|
||||||||
| #256 | prettier | 3.9.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #257 | @eslint/eslintrc | 3.3.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #258 | is-arrayish | 0.3.4 | 0.3.3 | Clear | Sep 15, 2025 Malware incident · Sep 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
The package has a notable security incident in its history: version 0.3.3 was compromised with malicious code following an npm account takeover, documented in both GHSA-frh7-2f84-v9mw and MAL-2025-46977. This was a supply chain attack where a legitimate package was hijacked to distribute malware, rather than a conventional vulnerability in the code itself. The issue has since been addressed, and the current release (0.3.4) is clear. Advisory history (2)
|
||||||||
| #259 | @jridgewell/sourcemap-codec | 1.5.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #260 | gensync | 1.0.0-beta.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #261 | word-wrap | 1.2.5 | - | Clear | Jun 22, 2023 | 1 |
1
moderate
|
|
|
AI-generated context
The word-wrap package has one historical advisory, GHSA-j8xg-fqg3-53r7, which identified a moderate-severity Regular Expression Denial of Service (ReDoS) vulnerability in older versions. This was a conventional vulnerability rather than malware. The issue has since been resolved, and the current release at version 1.2.5 is clear. Advisory history (1)
|
||||||||
| #262 | express | 5.2.1 | - | Clear | Oct 29, 2024 | 5 |
3
moderate
2
low
|
|
|
AI-generated context
Express has a history of conventional security vulnerabilities — no malware — spanning several years, including issues with missing charset declarations in Content-Type headers (GHSA-gpvr-g6gh-9mc2), open redirect flaws in malformed URLs (GHSA-rv95-896h-c2vc, GHSA-jj78-5fmv-mv28), an XSS vector via `response.redirect()` (GHSA-qw6h-vgh9-j6wx), and a resource injection issue (GHSA-cm5g-3pgc-8rg4). These were all moderate or low severity and reflect the kind of edge-case HTTP handling bugs common in mature web frameworks. The current release is clear, so developers using the latest version of Express are not exposed to these historical issues. Advisory history (5)
|
||||||||
| #263 | arg | 5.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #264 | jsonfile | 6.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #265 | schema-utils | 4.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #266 | @smithy/is-array-buffer | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #267 | @typescript-eslint/types | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #268 | chownr | 3.0.0 | - | Clear | Feb 10, 2022 | 1 |
1
low
|
|
|
AI-generated context
The chownr package has one historical advisory in its record, GHSA-c6rq-rjc2-86v2, which described a low-severity Time-of-check Time-of-use (TOCTOU) race condition vulnerability — a conventional security flaw, not malware. This issue has since been resolved, and the package's current release at version 3.0.0 is clear. Advisory history (1)
|
||||||||
| #269 | delayed-stream | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #270 | @smithy/util-buffer-from | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #271 | asynckit | 0.5.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #272 | tapable | 2.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #273 | enhanced-resolve | 5.24.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #274 | aria-query | 5.3.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #275 | indent-string | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #276 | bytes | 3.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #277 | binary-extensions | 3.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #278 | ini | 7.0.0 | - | Clear | Dec 10, 2020 | 1 |
1
high
|
|
|
AI-generated context
The `ini` package has one past high-severity advisory (GHSA-qqgx-2p2h-9c37) involving a Prototype Pollution vulnerability in the `ini.parse` function, which affected versions prior to 1.3.6. This was a conventional security vulnerability, not malware. The package's current release is clear, so developers depending on an up-to-date version are not exposed to this issue. Advisory history (1)
|
||||||||
| #279 | @radix-ui/react-context | 1.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #280 | doctrine | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #281 | queue-microtask | 1.2.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #282 | accepts | 1.3.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #283 | merge2 | 1.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #284 | get-caller-file | 2.0.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #285 | @humanwhocodes/retry | 0.4.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #286 | @jridgewell/gen-mapping | 0.3.13 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #287 | @typescript-eslint/typescript-estree | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #288 | jest-worker | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #289 | proxy-from-env | 2.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #290 | clsx | 2.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #291 | side-channel-map | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #292 | @typescript-eslint/visitor-keys | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #293 | fresh | 0.5.2 | - | Clear | Jul 24, 2018 | 1 |
1
high
|
|
|
AI-generated context
The `fresh` package has one historical advisory in its record, GHSA-9qj9-36jm-prpv, a high-severity Regular Expression Denial of Service vulnerability published in 2018. This was a conventional vulnerability, not malware, meaning a crafted input could cause excessive backtracking in a regular expression and degrade performance. The issue has since been addressed, and the current release (0.5.2) is clear. Advisory history (1)
|
||||||||
| #294 | restore-cursor | 5.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #295 | on-finished | 2.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #296 | is-plain-obj | 4.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #297 | ipaddr.js | 2.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #298 | pathe | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #299 | @jest/schemas | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #300 | base64-js | 1.5.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #301 | @smithy/types | 4.16.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #302 | require-directory | 2.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #303 | tough-cookie | 6.0.2 | - | Clear | Jul 01, 2023 | 3 |
1
high
2
moderate
|
|
|
AI-generated context
tough-cookie has a history of conventional security vulnerabilities, including two Regular Expression Denial of Service (ReDoS) issues (GHSA-g7q5-pjjr-gqvp, GHSA-qhv9-728r-6jqg) reported in 2018 and a moderate Prototype Pollution vulnerability (GHSA-72xf-g2v4-qvf3) disclosed in 2023. None of these advisories involved malware. The package's current release at version 6.0.2 is clear, so developers depending on it today can do so without concern from these past issues. Advisory history (3)
|
||||||||
| #304 | is-binary-path | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #305 | body-parser | 2.3.0 | - | Clear | Jul 20, 2026 | 3 |
1
high
1
moderate
1
low
|
|
|
Advisory history (3)
|
||||||||
| #306 | postcss-value-parser | 4.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #307 | media-typer | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #308 | setprototypeof | 1.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #309 | side-channel-weakmap | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #310 | @typescript-eslint/tsconfig-utils | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #311 | @isaacs/cliui | 9.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #312 | @rollup/rollup-linux-x64-gnu | 4.62.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #313 | is-wsl | 3.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #314 | retry | 0.13.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #315 | @aws-sdk/types | 3.974.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #316 | @types/react-dom | 19.2.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #317 | combined-stream | 1.0.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #318 | es-object-atoms | 1.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #319 | @eslint/core | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #320 | whatwg-mimetype | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #321 | domutils | 4.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #322 | @rollup/rollup-linux-x64-musl | 4.62.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #323 | core-util-is | 1.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #324 | @typescript-eslint/scope-manager | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #325 | esprima | 4.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #326 | loose-envify | 1.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #327 | cookie-signature | 1.2.2 | - | Clear | Jan 06, 2020 | 1 |
1
moderate
|
|
|
AI-generated context
The package has one advisory in its history, GHSA-92vm-wfm5-mxvv, which flagged a moderate-severity timing attack vulnerability in cookie-signature — a conventional cryptographic flaw rather than malware. This issue has since been resolved, and the package's current release at version 1.2.2 is clear. Advisory history (1)
|
||||||||
| #328 | follow-redirects | 1.16.0 | - | Clear | Apr 14, 2026 | 5 |
1
high
4
moderate
|
|
|
AI-generated context
The follow-redirects package has accumulated several conventional security vulnerabilities over the years, none involving malware, centered primarily on the improper handling of sensitive information — including advisories GHSA-74fj-2j2h-c42q and GHSA-pw2r-vq6v-hr8c covering exposure of sensitive data, and multiple issues around authentication headers being leaked to unintended hosts during redirects. Additional advisories flagged problems with URL parsing and Proxy-Authorization headers being forwarded across different domains. The current release at version 1.16.0 is clear, so developers depending on it today should ensure they are on the latest version to benefit from the fixes addressing this history of redirect-related information disclosure issues. Advisory history (5)
|
||||||||
| #329 | cli-cursor | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #330 | strip-final-newline | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #331 | @typescript-eslint/project-service | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #332 | eastasianwidth | 0.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #333 | json-parse-even-better-errors | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #334 | sprintf-js | 1.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #335 | path-type | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #336 | content-type | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #337 | es-module-lexer | 2.3.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #338 | @nodelib/fs.scandir | 4.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #339 | write-file-atomic | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #340 | @eslint/plugin-kit | 0.7.2 | - | Clear | Jul 18, 2025 | 2 |
2
low
|
|
|
AI-generated context
The advisory history for `@eslint/plugin-kit` consists entirely of conventional (non-malware) vulnerabilities — specifically two low-severity Regular Expression Denial of Service (ReDoS) issues (GHSA-7q7g-4xm8-89cq and GHSA-xffm-g5w8-qvg7), one affecting general regex handling and one targeting the `ConfigCommentParser`. Both have since been addressed, and the package's current release at version 0.7.2 is clear, making it safe to depend on today. Advisory history (2)
|
||||||||
| #341 | ieee754 | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #342 | prop-types | 15.8.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #343 | require-from-string | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #344 | dom-serializer | 3.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #345 | call-bind | 1.0.9 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #346 | @eslint/config-array | 0.23.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #347 | has-property-descriptors | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #348 | @nodelib/fs.stat | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #349 | merge-descriptors | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #350 | slice-ansi | 9.0.0 | 7.1.1 | Clear | Sep 08, 2025 Malware incident · Sep 2025 | 1 |
1
malware
|
|
|
AI-generated context
Advisory MAL-2025-46979 flagged a malicious version of slice-ansi on npm, indicating the package was at some point compromised with malicious code. This is a historical finding and the package's current latest release, version 9.0.0, is clear, so developers using that version are not affected. Advisory history (1)
|
||||||||
| #351 | rxjs | 7.8.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #352 | p-map | 7.0.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #353 | toidentifier | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #354 | globby | 16.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #355 | domhandler | 6.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #356 | async | 3.2.6 | - | Clear | Apr 07, 2022 | 1 |
1
high
|
|
|
AI-generated context
The `async` package has one historical advisory in its record, GHSA-fwr7-v2mv-hh25, a high-severity prototype pollution vulnerability that was disclosed in April 2022. This was a conventional vulnerability rather than malware, affecting how the library handled certain object inputs in a way that could allow attackers to manipulate JavaScript object prototypes. The package's latest release is clear, so developers on an up-to-date version are not exposed to this issue. Advisory history (1)
|
||||||||
| #357 | @babel/helper-globals | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #358 | pirates | 4.0.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #359 | @opentelemetry/semantic-conventions | 1.43.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #360 | @typescript-eslint/utils | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #361 | date-fns | 4.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #362 | is-docker | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #363 | tar | 7.5.22 | 7.5.1 | Clear | Jul 24, 2026 | 21 |
1
critical
14
high
6
moderate
|
|
|
Advisory history (21)
|
||||||||
| #364 | which-typed-array | 1.1.22 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #365 | ajv-formats | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #366 | @opentelemetry/api-logs | 0.221.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #367 | @opentelemetry/resources | 2.10.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #368 | side-channel | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #369 | cjs-module-lexer | 2.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #370 | range-parser | 1.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #371 | @humanfs/node | 0.16.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #372 | define-data-property | 1.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #373 | node-addon-api | 8.9.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #374 | pako | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #375 | lilconfig | 3.1.3 | - | Clear | Oct 31, 2024 | 1 |
1
high
|
|
|
AI-generated context
Lilconfig has one advisory in its history, GHSA-fq9m-v26v-2m4f, a high-severity code injection vulnerability published in late 2024. This was a conventional security flaw, not malware. The package is clear at its latest release, version 3.1.3, so developers on the current version are not affected by that past issue. Advisory history (1)
|
||||||||
| #376 | fast-uri | 4.1.1 | - | Clear | Jul 21, 2026 | 4 |
4
high
|
|
|
Advisory history (4)
|
||||||||
| #377 | ip-address | 10.3.1 | - | Clear | May 05, 2026 | 1 |
1
moderate
|
|
|
AI-generated context
The `ip-address` package has one historical advisory (GHSA-v2v4-37r5-5v8g) involving a moderate-severity cross-site scripting (XSS) vulnerability in the Address6 HTML-emitting methods, a conventional security flaw rather than malware. This issue has since been resolved, and the package's current release at version 10.2.0 is clear. Advisory history (1)
|
||||||||
| #378 | fs.realpath | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #379 | @img/sharp-libvips-linuxmusl-x64 | 1.3.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #380 | cssesc | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #381 | @opentelemetry/instrumentation | 0.221.0 | - | Clear | Aug 09, 2023 | 1 |
1
high
|
|
|
AI-generated context
The package has one historical advisory, GHSA-f8pq-3926-8gx5, a high-severity vulnerability involving unsanitized user-controlled input in module generation, not malware. This was a conventional security flaw that has since been addressed, and the package currently ships at version 0.220.0 with a clear status. Developers depending on this package today can do so with confidence, provided they are on a sufficiently recent release. Advisory history (1)
|
||||||||
| #382 | domelementtype | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #383 | hosted-git-info | 10.1.1 | - | Clear | May 06, 2021 | 1 |
1
moderate
|
|
|
AI-generated context
The package hosted-git-info has one historical advisory in its record, GHSA-43f8-2h32-f4cj, which described a moderate-severity Regular Expression Denial of Service vulnerability — a conventional flaw with no malware involvement. This issue has since been addressed, and the package's current release is clear, making it safe to depend on today. Advisory history (1)
|
||||||||
| #384 | @eslint/object-schema | 3.0.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #385 | etag | 1.8.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #386 | @eslint/config-helpers | 0.7.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #387 | package-json-from-dist | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #388 | @humanfs/core | 0.19.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #389 | htmlparser2 | 12.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #390 | jest-message-util | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #391 | for-each | 0.3.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #392 | pkg-dir | 9.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #393 | unpipe | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #394 | buffer-from | 1.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #395 | es-abstract | 1.24.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #396 | is-unicode-supported | 2.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #397 | @types/yargs | 17.0.35 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #398 | is-callable | 1.2.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #399 | fast-xml-parser | 5.10.1 | 4.2.4 | Clear | Jul 21, 2026 | 12 |
1
critical
6
high
3
moderate
2
low
|
|
|
Advisory history (12)
|
||||||||
| #400 | istanbul-lib-instrument | 6.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #401 | escape-html | 1.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #402 | is-regex | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #403 | dom-accessibility-api | 0.7.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #404 | css-tree | 3.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #405 | error-ex | 1.3.4 | 1.3.3 | Clear | Sep 15, 2025 Malware incident · Sep 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
The package experienced a serious security incident in which version 1.3.3 was compromised with malicious code following an npm account takeover, documented in both GHSA-6jp5-hh4c-8c5h and MAL-2025-46975. This was a supply chain attack involving actual malware injected into a published release, not a conventional vulnerability. The latest release, 1.3.4, is clear, but developers should ensure they are not pinned to the affected 1.3.3 version. Advisory history (2)
|
||||||||
| #406 | ee-first | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #407 | @types/unist | 3.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #408 | log-symbols | 7.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #409 | path-is-absolute | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #410 | end-of-stream | 1.4.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #411 | @vitest/utils | 4.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #412 | object.assign | 4.1.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #413 | object-keys | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #414 | tinyexec | 1.2.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #415 | scheduler | 0.27.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #416 | p-try | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #417 | process-nextick-args | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #418 | vary | 1.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #419 | @babel/traverse | 8.0.4 | - | Clear | Oct 16, 2023 | 1 |
1
critical
|
|
|
AI-generated context
@babel/traverse has one critical advisory in its history (GHSA-67hx-6x53-jw92), which identified an arbitrary code execution vulnerability triggered when the compiler processed specially crafted malicious input. This was a conventional vulnerability rather than malware, and it has since been resolved. The package's current release is clear, so developers on an up-to-date version are not exposed to this issue. Advisory history (1)
|
||||||||
| #420 | @pkgjs/parseargs | 0.11.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #421 | @types/babel__generator | 7.27.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #422 | kleur | 4.1.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #423 | zod | 4.4.3 | - | Clear | Sep 28, 2023 | 1 |
1
moderate
|
|
|
AI-generated context
Zod has one advisory in its history, GHSA-m95q-7qp3-xv42, a moderate-severity denial of service vulnerability published in September 2023. This was a conventional vulnerability with no malware involvement, and it has since been resolved. Developers depending on the current release can do so with confidence, as the package is now clear. Advisory history (1)
|
||||||||
| #424 | merge-stream | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #425 | available-typed-arrays | 1.0.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #426 | mute-stream | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #427 | is-typed-array | 1.1.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #428 | safe-regex-test | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #429 | tsconfig-paths | 4.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #430 | minizlib | 3.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #431 | tar-stream | 3.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #432 | @floating-ui/core | 1.8.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #433 | jose | 6.2.4 | - | Clear | Mar 07, 2024 | 3 |
3
moderate
|
|
|
AI-generated context
The `jose` package has a history of three moderate-severity conventional vulnerabilities, none involving malware: a padding oracle attack via observable timing discrepancy (GHSA-58f5-hfqc-jgch), and two separate resource exhaustion issues triggered by specially crafted JWE inputs (GHSA-jv3g-j58f-9mq9 and GHSA-hhhv-q57g-882q). These vulnerabilities affected earlier releases and have since been addressed, as the current latest version is clear. Advisory history (3)
|
||||||||
| #434 | deepmerge | 4.3.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #435 | get-tsconfig | 4.14.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #436 | set-function-length | 1.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #437 | @vitest/spy | 4.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #438 | css-select | 7.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #439 | @types/babel__core | 7.20.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #440 | forwarded | 0.2.0 | - | Clear | Jul 24, 2018 | 1 |
1
high
|
|
|
AI-generated context
The `forwarded` package has one historical advisory in its record, GHSA-mpcf-4gmh-23w8, a high-severity Regular Expression Denial of Service vulnerability published in 2018. This was a conventional vulnerability rather than malware, where a crafted input could cause excessive backtracking in a regular expression. The package is currently clear at its latest release, meaning this issue has since been addressed. Advisory history (1)
|
||||||||
| #441 | react | 19.2.8 | - | Clear | Sep 04, 2020 | 2 |
1
high
1
moderate
|
|
|
AI-generated context
React has two historical cross-site scripting advisories in its past (GHSA-g53w-52xc-2j85 and GHSA-hg79-j56m-fxgv), both published in September 2020 and rated moderate and high severity respectively. These were conventional vulnerabilities, not malware, and have since been addressed. The package's current release is clear, so developers depending on an up-to-date version of react are not exposed to these issues. Advisory history (2)
|
||||||||
| #442 | @typescript-eslint/parser | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #443 | ajv-keywords | 5.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #444 | define-properties | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #445 | is-generator-function | 1.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #446 | regexp.prototype.flags | 1.5.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #447 | acorn-walk | 8.3.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #448 | pump | 3.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #449 | data-uri-to-buffer | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #450 | object-hash | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #451 | jsdom | 30.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #452 | nopt | 10.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #453 | @babel/plugin-syntax-jsx | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #454 | @floating-ui/dom | 1.8.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #455 | tiny-invariant | 1.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #456 | strip-indent | 4.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #457 | d3-array | 3.2.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #458 | chai | 6.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #459 | @babel/code-frame | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #460 | @typescript-eslint/eslint-plugin | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #461 | proxy-addr | 2.0.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #462 | parseurl | 1.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #463 | @floating-ui/utils | 0.2.12 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #464 | ora | 9.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #465 | html-encoding-sniffer | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #466 | pnpm | 11.17.0 | - | Clear | Jun 27, 2026 | 28 |
14
high
14
moderate
|
|
|
AI-generated context
pnpm has an extensive history of conventional security vulnerabilities — no malware — spanning issues such as path traversal in tarball and ZIP extraction, command injection via environment variable substitution, lockfile integrity bypasses, symlink traversal, and credential leakage to repository-controlled registries. Many of these were disclosed in coordinated batches, with a particularly large set published in June 2026 alongside earlier advisories going back to 2022. The current release (11.15.0) is clear, meaning developers who keep pnpm up to date can rely on these issues having been addressed in prior versions. Advisory history (28)
|
||||||||
| #467 | whatwg-encoding | 3.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #468 | events | 3.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #469 | @typescript-eslint/type-utils | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #470 | env-paths | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #471 | internal-slot | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #472 | string.prototype.trimend | 1.0.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #473 | extend | 3.0.2 | - | Clear | Feb 07, 2019 | 1 |
1
moderate
|
|
|
AI-generated context
The `extend` package has one advisory in its history, GHSA-qrmc-fj45-qfc2, a moderate-severity prototype pollution vulnerability, which is a conventional security flaw rather than malware. This issue has since been addressed, and the package's current release (3.0.2) is clear. Developers depending on `extend` today should simply ensure they are on an up-to-date version. Advisory history (1)
|
||||||||
| #474 | resolve-pkg-maps | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #475 | istanbul-lib-coverage | 3.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #476 | react-dom | 19.2.8 | 16.2.0 | Clear | Jan 04, 2019 | 1 |
1
moderate
|
|
|
AI-generated context
React-dom has one historical advisory in its record, GHSA-mvjj-gqq2-p4hw, a moderate-severity cross-site scripting vulnerability published in early 2019. This was a conventional security flaw, not malware, and has since been addressed. The package's current release is clear, making this a resolved piece of history rather than an ongoing concern for developers depending on it today. Advisory history (1)
|
||||||||
| #477 | is-number-object | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #478 | @radix-ui/primitive | 1.1.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #479 | is-plain-object | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #480 | string.prototype.trimstart | 1.0.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #481 | @babel/plugin-syntax-typescript | 8.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #482 | jest-diff | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #483 | define-lazy-prop | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #484 | globalthis | 1.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #485 | which-boxed-primitive | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #486 | @vitest/expect | 4.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #487 | sax | 1.6.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #488 | @floating-ui/react-dom | 2.1.9 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #489 | @vitest/pretty-format | 4.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #490 | internmap | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #491 | @radix-ui/react-compose-refs | 1.1.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #492 | is-symbol | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #493 | @eslint-community/eslint-utils | 4.10.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #494 | bl | 7.0.10 | 3.0.0 | Clear | Sep 02, 2020 | 2 |
2
moderate
|
|
|
AI-generated context
The `bl` package has two historical moderate-severity advisories in its past — GHSA-wrw9-m778-g6mc and GHSA-pp7h-53gx-mx7r — both involving memory exposure vulnerabilities where improper handling of buffer data could leak sensitive information to remote parties. These were conventional security flaws, not malware, and both have since been addressed. The current release is clear, making `bl` safe to use for developers today. Advisory history (2)
|
||||||||
| #495 | serve-static | 2.2.1 | - | Clear | Sep 10, 2024 | 2 |
2
low
|
|
|
AI-generated context
The `serve-static` package has two historical low-severity vulnerability advisories in its past: an open redirect issue (GHSA-c3x7-gjmx-r2ff) and a template injection flaw that could lead to cross-site scripting (GHSA-cm22-4g7w-348p). Both were conventional vulnerabilities rather than malware, reflecting the kinds of edge-case security issues common in widely used static file serving middleware. The current release at version 2.2.1 is clear, so developers depending on the latest version are not affected by either of these historical issues. Advisory history (2)
|
||||||||
| #496 | get-symbol-description | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #497 | is-shared-array-buffer | 1.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #498 | functions-have-names | 1.2.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #499 | array-buffer-byte-length | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #500 | socks-proxy-agent | 10.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #501 | extend-shallow | 3.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #502 | @radix-ui/react-use-layout-effect | 1.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #503 | function.prototype.name | 1.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #504 | is-bigint | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #505 | is-string | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #506 | protobufjs | 8.7.1 | - | Clear | Jul 20, 2026 | 17 |
2
critical
6
high
9
moderate
|
|
|
Advisory history (17)
|
||||||||
| #507 | tmp | 0.2.7 | - | Clear | Jun 15, 2026 | 3 |
2
high
1
low
|
|
|
AI-generated context
The `tmp` package has a history of conventional security vulnerabilities — no malware — covering symlink-based arbitrary file writes (GHSA-52f5-9888-hmc6) and two high-severity path traversal issues involving unsanitized prefix/postfix parameters and type-confusion bypasses (GHSA-ph9p-34f9-6g65, GHSA-7c78-jf6q-g5cm). These were vulnerabilities in how temporary file and directory paths were constructed and validated. The current release at version 0.2.7 is clear, meaning these issues have been addressed in the latest version. Advisory history (3)
|
||||||||
| #508 | is-date-object | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #509 | lightningcss-linux-x64-musl | 1.33.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #510 | proc-log | 7.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #511 | long | 5.3.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #512 | @opentelemetry/sdk-trace-base | 2.10.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #513 | nth-check | 3.0.1 | - | Clear | Sep 20, 2021 | 1 |
1
high
|
|
|
AI-generated context
nth-check has one historical advisory in its record, GHSA-rp65-9cf3-cjxr, a high-severity vulnerability involving inefficient regular expression complexity (ReDoS) that was disclosed in 2021. This was a conventional vulnerability, not malware, affecting how the package processed certain CSS nth-check expressions. The current release, version 3.0.1, is clear of this issue, so developers on the latest version are not affected. Advisory history (1)
|
||||||||
| #514 | d3-path | 3.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #515 | @types/babel__template | 7.4.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #516 | jest-regex-util | 30.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #517 | @radix-ui/react-use-controllable-state | 1.2.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #518 | jest-mock | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #519 | socks | 2.8.9 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #520 | lightningcss | 1.33.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #521 | assertion-error | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #522 | es-to-primitive | 1.3.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #523 | tinyrainbow | 3.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #524 | possible-typed-array-names | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #525 | figures | 6.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #526 | xml-name-validator | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #527 | any-promise | 1.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #528 | d3-shape | 3.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #529 | terser | 5.49.0 | - | Clear | Jul 16, 2022 | 1 |
1
high
|
|
|
AI-generated context
Terser has one historical advisory in its record (GHSA-4wf5-vphf-c2xc), a high-severity conventional vulnerability involving insecure regular expression usage that could lead to a ReDoS (Regular Expression Denial of Service) attack. This was not a malware issue and has since been addressed, with the package's current release at version 5.49.0 carrying a clear status. Advisory history (1)
|
||||||||
| #530 | std-env | 4.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #531 | is-array-buffer | 3.0.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #532 | safe-array-concat | 1.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #533 | @aws-sdk/token-providers | 3.1097.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #534 | data-urls | 7.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #535 | d3-interpolate | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #536 | @radix-ui/react-dismissable-layer | 1.1.19 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #537 | set-function-name | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #538 | css-what | 8.0.0 | - | Clear | Oct 01, 2022 | 2 |
2
high
|
|
|
AI-generated context
The css-what package has two historical high-severity advisories (GHSA-p28h-cc7q-c4fg and GHSA-q8pj-2vqx-8ggc), both involving denial-of-service vulnerabilities caused by insecure regular expressions susceptible to ReDoS attacks. These were conventional vulnerabilities with no malware involvement. The package's latest release is clear, so developers on version 8.0.0 are not affected by these past issues. Advisory history (2)
|
||||||||
| #539 | typed-array-length | 1.0.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #540 | typed-array-byte-offset | 1.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #541 | thenify | 3.3.1 | - | Clear | Jul 18, 2022 | 1 |
1
critical
|
|
|
AI-generated context
The thenify package has one historical advisory (GHSA-29xr-v42j-r956) in its record, a critical-severity issue involving unsafe calls to `eval` that affected versions before 3.3.1. This was a conventional vulnerability rather than malware, and it was resolved in version 3.3.1, which is the current release and carries a clear status. Advisory history (1)
|
||||||||
| #542 | mz | 2.7.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #543 | react-remove-scroll | 2.7.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #544 | @radix-ui/react-id | 1.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #545 | is-weakset | 2.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #546 | is-boolean-object | 1.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #547 | @alloc/quick-lru | 5.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #548 | html-escaper | 3.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #549 | has-bigints | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #550 | @aws-sdk/credential-provider-node | 3.972.74 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #551 | lightningcss-linux-x64-gnu | 1.33.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #552 | @radix-ui/react-presence | 1.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #553 | w3c-xmlserializer | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #554 | istanbul-reports | 3.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #555 | @babel/helper-annotate-as-pure | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #556 | typed-array-buffer | 1.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #557 | @nodelib/fs.walk | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #558 | sharp | 0.35.3 | - | Clear | Jul 21, 2026 | 3 |
2
high
1
moderate
|
|
|
Advisory history (3)
|
||||||||
| #559 | arraybuffer.prototype.slice | 1.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #560 | d3-format | 3.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #561 | has-proto | 1.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #562 | d3-timer | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #563 | lodash.isplainobject | 4.0.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #564 | @aws-sdk/util-endpoints | 3.996.36 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #565 | @radix-ui/react-use-callback-ref | 1.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #566 | d3-time-format | 4.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #567 | is-weakref | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #568 | autoprefixer | 10.5.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #569 | istanbul-lib-report | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #570 | postcss-load-config | 6.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #571 | strnum | 2.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #572 | core-js | 3.49.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #573 | @vitest/snapshot | 4.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #574 | @aws-sdk/credential-provider-env | 3.972.63 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #575 | define-property | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #576 | @sinonjs/fake-timers | 15.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #577 | @aws-sdk/credential-provider-web-identity | 3.972.69 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #578 | clone | 2.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #579 | normalize-package-data | 9.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #580 | d3-color | 3.1.0 | - | Clear | Sep 29, 2022 | 1 |
1
high
|
|
|
AI-generated context
d3-color has one advisory in its history, GHSA-36jr-mh4h-2g58, a high-severity regular expression denial-of-service (ReDoS) vulnerability affecting earlier versions of the package. This was a conventional vulnerability rather than malware, and it has since been addressed. The current release, version 3.1.0, is clear, so developers depending on an up-to-date version of d3-color are not affected by this issue. Advisory history (1)
|
||||||||
| #581 | d3-time | 3.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #582 | colorette | 2.0.20 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #583 | is-negative-zero | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #584 | unbox-primitive | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #585 | data-view-byte-length | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #586 | data-view-buffer | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #587 | regenerator-runtime | 0.14.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #588 | is-set | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #589 | saxes | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #590 | decimal.js | 10.6.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #591 | @aws-sdk/core | 3.977.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #592 | @radix-ui/react-portal | 1.1.17 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #593 | d3-scale | 4.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #594 | dequal | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #595 | which-collection | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #596 | cli-width | 4.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #597 | @radix-ui/react-use-escape-keydown | 1.1.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #598 | @swc/helpers | 0.5.23 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #599 | data-view-byte-offset | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #600 | @aws-sdk/util-user-agent-node | 3.973.53 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #601 | is-map | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #602 | is-path-inside | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #603 | xtend | 4.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #604 | is-finalizationregistry | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #605 | import-in-the-middle | 3.3.2 | - | Clear | Aug 08, 2023 | 1 |
1
high
|
|
|
AI-generated context
The package has one historical advisory in its record, GHSA-5r27-rw8r-7967, a high-severity vulnerability involving unsanitized user-controlled input during module generation. This was a conventional security flaw rather than malware. The package's latest release is currently clear, so developers depending on an up-to-date version are not affected by this past issue. Advisory history (1)
|
||||||||
| #606 | xmlbuilder | 15.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #607 | @sinclair/typebox | 0.34.52 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #608 | is-async-function | 2.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #609 | tsx | 4.23.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #610 | d3-ease | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #611 | jwa | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #612 | @aws-sdk/middleware-user-agent | 3.972.67 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #613 | @types/express-serve-static-core | 5.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #614 | thenify-all | 1.6.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #615 | @jridgewell/remapping | 2.3.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #616 | @vitest/runner | 4.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #617 | decamelize | 6.0.1 | - | Clear | Jul 24, 2018 | 1 |
1
high
|
|
|
AI-generated context
The decamelize package has one historical advisory, GHSA-q5c4-39f5-m68j, which flagged a high-severity Regular Expression Denial of Service vulnerability published in 2018. This was a conventional vulnerability, not malware, where a crafted input could cause excessive backtracking in a regular expression. The issue has since been resolved, and the current release (6.0.1) is clear. Advisory history (1)
|
||||||||
| #618 | clean-stack | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #619 | abbrev | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #620 | @aws-sdk/middleware-logger | 3.972.37 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #621 | type-detect | 4.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #622 | @radix-ui/react-collection | 1.1.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #623 | @radix-ui/react-focus-scope | 1.1.16 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #624 | loader-utils | 3.3.1 | - | Clear | Oct 14, 2022 | 3 |
1
critical
2
high
|
|
|
AI-generated context
The loader-utils package has a history of three conventional security vulnerabilities discovered in October 2022, including two high-severity ReDoS issues (GHSA-3rfm-jhwj-7488 and GHSA-hhq3-ff78-jv3g) and a critical prototype pollution vulnerability (GHSA-76p3-8jx3-jpfq). No malware was ever involved. These issues have since been addressed, and the current release at version 3.3.1 is clear. Advisory history (3)
|
||||||||
| #625 | mimic-response | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #626 | string.prototype.trim | 1.2.11 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #627 | fraction.js | 5.3.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #628 | ast-types | 0.14.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #629 | which-builtin-type | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #630 | array-includes | 3.1.9 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #631 | @bcoe/v8-coverage | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #632 | expect | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #633 | @types/d3-shape | 3.1.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #634 | @smithy/protocol-http | 5.5.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #635 | cli-spinners | 3.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #636 | @types/d3-time | 3.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #637 | @types/d3-color | 3.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #638 | @radix-ui/react-focus-guards | 1.1.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #639 | sucrase | 3.35.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #640 | typed-array-byte-length | 1.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #641 | @radix-ui/react-popper | 1.3.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #642 | aria-hidden | 1.2.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #643 | escodegen | 2.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #644 | @types/d3-array | 3.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #645 | bn.js | 5.2.5 | - | Clear | Feb 20, 2026 | 1 |
1
moderate
|
|
|
AI-generated context
bn.js has one historical advisory in its record, GHSA-378v-28hj-76wf, which described a moderate-severity infinite loop vulnerability — a conventional bug rather than any malicious code. This issue has since been resolved, and the package's current release at version 5.2.5 is clear. Advisory history (1)
|
||||||||
| #646 | split2 | 4.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #647 | http-cache-semantics | 4.2.0 | - | Clear | Jan 31, 2023 | 1 |
1
high
|
|
|
AI-generated context
The package has one historical advisory (GHSA-rc47-6667-2j5j), a high-severity Regular Expression Denial of Service vulnerability, which was a conventional security flaw rather than malware. This issue has since been resolved, and the current release at version 4.2.0 is clear, making it safe to use as a dependency today. Advisory history (1)
|
||||||||
| #648 | utils-merge | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #649 | buffer-crc32 | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #650 | boolbase | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #651 | @smithy/fetch-http-handler | 5.6.12 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #652 | @types/d3-path | 3.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #653 | @ungap/structured-clone | 1.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #654 | @radix-ui/react-direction | 1.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #655 | react-remove-scroll-bar | 2.3.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #656 | @types/send | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #657 | mdn-data | 2.29.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #658 | cors | 2.8.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #659 | @types/express | 5.0.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #660 | is-weakmap | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #661 | reflect.getprototypeof | 1.0.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #662 | jest-haste-map | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #663 | eslint-config-prettier | 10.1.8 | 10.1.7 | Clear | Jul 21, 2025 Malware incident · Jul 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
The package has two advisories in its history — GHSA-f29h-pxvx-f335 and MAL-2025-6022 — both related to a malicious code incident that affected eslint-config-prettier along with several other packages. These advisories flagged embedded malware in affected versions, making it a supply-chain compromise rather than a conventional vulnerability. The current latest release (10.1.8) is clear, so developers using that version are not exposed to those issues. Advisory history (2)
|
||||||||
| #664 | postcss-import | 16.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #665 | neo-async | 2.6.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #666 | array-union | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #667 | ssri | 14.0.0 | 8.0.0 | Clear | Mar 19, 2021 | 2 |
1
high
1
moderate
|
|
|
AI-generated context
The `ssri` package has two historical advisories in its past, both involving Regular Expression Denial of Service (ReDoS) vulnerabilities (GHSA-325j-24f4-qv5x and GHSA-vx3p-948g-6vhq), with the latter rated high severity. These were conventional security flaws, not malware, and both have since been addressed. The current release at version 14.0.0 is clear, so developers can depend on it without concern from these past issues. Advisory history (2)
|
||||||||
| #668 | @types/d3-interpolate | 3.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #669 | @aws-sdk/middleware-host-header | 3.972.38 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #670 | @radix-ui/react-visually-hidden | 1.2.11 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #671 | @babel/helper-replace-supers | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #672 | @radix-ui/react-arrow | 1.1.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #673 | stop-iteration-iterator | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #674 | @aws-sdk/credential-provider-process | 3.972.63 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #675 | istanbul-lib-source-maps | 5.0.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #676 | dedent | 1.7.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #677 | is-data-view | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #678 | @smithy/signature-v4 | 5.6.11 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #679 | redent | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #680 | @aws-sdk/credential-provider-http | 3.972.65 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #681 | is-promise | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #682 | object.values | 1.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #683 | @istanbuljs/schema | 0.1.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #684 | @sindresorhus/is | 8.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #685 | own-keys | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #686 | @jest/fake-timers | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #687 | safe-push-apply | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #688 | cssstyle | 6.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #689 | destroy | 1.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #690 | @jest/transform | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #691 | react-transition-group | 4.4.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #692 | @babel/helper-member-expression-to-functions | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #693 | ts-interface-checker | 1.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #694 | dom-helpers | 6.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #695 | @opentelemetry/api | 1.9.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #696 | @img/sharp-linux-x64 | 0.35.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #697 | isobject | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #698 | array.prototype.flatmap | 1.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #699 | @types/ws | 8.18.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #700 | es-shim-unscopables | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #701 | vitest | 4.1.10 | 0.0.125 | Clear | Jun 01, 2026 | 2 |
2
critical
|
|
|
AI-generated context
Vitest has two critical conventional vulnerability advisories in its history: GHSA-9crc-q9x8-hgqq, involving remote code execution when a malicious website is visited while the Vitest API server is listening, and GHSA-5xrq-8626-4rwp, allowing arbitrary file reading and execution when the Vitest UI server is active. Both issues stemmed from the exposure of internal server interfaces rather than malware. These vulnerabilities have since been addressed, and the current release is clear. Advisory history (2)
|
||||||||
| #702 | array.prototype.flat | 1.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #703 | @babel/plugin-syntax-import-attributes | 7.29.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #704 | gcp-metadata | 8.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #705 | @emnapi/runtime | 1.11.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #706 | @types/chai | 5.2.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #707 | @types/prop-types | 15.7.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #708 | @types/d3-ease | 3.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #709 | @babel/helper-create-class-features-plugin | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #710 | @radix-ui/react-roving-focus | 1.1.19 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #711 | @jest/environment | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #712 | jest-matcher-utils | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #713 | symbol-tree | 3.2.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #714 | detect-node-es | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #715 | test-exclude | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #716 | dlv | 1.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #717 | @vitest/mocker | 4.1.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #718 | @smithy/property-provider | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #719 | xmlchars | 2.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #720 | webpack-sources | 3.5.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #721 | @smithy/util-middleware | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #722 | shell-quote | 1.10.0 | - | Clear | Jul 20, 2026 | 4 |
3
critical
1
high
|
|
|
Advisory history (4)
|
||||||||
| #723 | smart-buffer | 4.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #724 | set-proto | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #725 | graphemer | 1.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #726 | @aws-sdk/region-config-resolver | 3.972.41 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #727 | @aws-sdk/util-user-agent-browser | 3.972.38 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #728 | gaxios | 7.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #729 | is-extendable | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #730 | @radix-ui/react-dialog | 1.1.23 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #731 | vite | 8.1.5 | 4.5.0 | Clear | Jun 15, 2026 | 22 |
7
high
13
moderate
2
low
|
|
|
AI-generated context
Vite has an extensive history of conventional (non-malware) security vulnerabilities, the large majority of which involve bypasses of the `server.fs.deny` file-access restriction in its development server, achieved through techniques like double slashes, query string manipulation, case-insensitive filesystem tricks, path traversal, and Windows-specific alternate paths (e.g., GHSA-353f-5xf4-qw67, GHSA-fx2h-pf6j-xcff). Additional advisories cover XSS issues, arbitrary file read via WebSocket, and command injection through a bundled `launch-editor` dependency. All known vulnerabilities have been addressed in prior releases, and the current version 8.1.5 is clear. Advisory history (22)
|
||||||||
| #732 | get-nonce | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #733 | is-potential-custom-element-name | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #734 | @types/d3-timer | 3.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #735 | @smithy/querystring-builder | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #736 | inflight | 1.0.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #737 | @radix-ui/react-use-size | 1.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #738 | leven | 4.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #739 | @tailwindcss/oxide-linux-x64-musl | 4.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #740 | @aws-sdk/middleware-recursion-detection | 3.972.39 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #741 | read-cache | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #742 | @types/ms | 2.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #743 | @aws-sdk/xml-builder | 3.972.37 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #744 | google-auth-library | 10.9.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #745 | why-is-node-running | 3.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #746 | aggregate-error | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #747 | setimmediate | 1.0.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #748 | read-pkg | 10.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #749 | @smithy/smithy-client | 4.14.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #750 | react-hook-form | 7.83.0 | 7.73.0 | Clear | Apr 18, 2026 Malware incident · Apr 2026 | 1 |
1
malware
|
|
|
AI-generated context
React-hook-form was flagged in advisory MAL-2026-2853 for containing malicious code in a version published to npm. This was a malware incident rather than a conventional vulnerability, meaning a compromised or tampered version of the package had been distributed. The current release, 7.82.0, is clear, so developers using the latest version are not affected by that historical incident. Advisory history (1)
|
||||||||
| #751 | methods | 1.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #752 | @sinonjs/commons | 4.0.0-alpha.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #753 | object.entries | 1.1.9 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #754 | babel-jest | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #755 | @types/serve-static | 2.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #756 | is-interactive | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #757 | event-target-shim | 6.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #758 | jest-get-type | 29.6.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #759 | postcss-js | 5.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #760 | @rollup/pluginutils | 5.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #761 | tldts-core | 7.4.9 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #762 | class-variance-authority | 0.7.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #763 | @napi-rs/wasm-runtime | 1.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #764 | @openai/codex | 0.146.0 | 0.23.0 | Clear | Apr 14, 2026 | 2 |
1
critical
1
high
|
|
|
AI-generated context
The @openai/codex package has two historical security advisories involving conventional vulnerabilities rather than malware: a high-severity sandbox bypass caused by a bug in path configuration logic (GHSA-w5fx-fh39-j5rw) and a critical-severity issue allowing code execution through malicious MCP configuration files (GHSA-xrxf-jgv3-qmrm). Both advisories reflect the security-sensitive nature of an AI coding CLI tool with sandbox and execution capabilities. The current release at version 0.144.6 is clear, indicating these issues have been addressed. Advisory history (2)
|
||||||||
| #765 | @jest/console | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #766 | @radix-ui/react-use-previous | 1.1.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #767 | pure-rand | 8.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #768 | object.fromentries | 2.0.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #769 | babel-plugin-istanbul | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #770 | dir-glob | 3.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #771 | siginfo | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #772 | jest-validate | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #773 | @smithy/middleware-endpoint | 4.6.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #774 | babel-plugin-polyfill-corejs3 | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #775 | @types/istanbul-lib-coverage | 2.0.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #776 | babel-plugin-jest-hoist | 30.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #777 | async-function | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #778 | array-flatten | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #779 | didyoumean | 1.2.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #780 | tinybench | 6.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #781 | get-east-asian-width | 1.6.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #782 | @smithy/shared-ini-file-loader | 4.6.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #783 | dayjs | 1.11.21 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #784 | recharts | 3.10.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #785 | @jest/test-result | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #786 | @radix-ui/rect | 1.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #787 | @octokit/types | 16.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #788 | @babel/plugin-transform-react-jsx-source | 7.29.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #789 | @tootallnate/once | 3.0.1 | - | Clear | Mar 03, 2026 | 1 |
1
low
|
|
|
AI-generated context
@tootallnate/once has one advisory in its history, GHSA-vpq2-c234-7xj6, a low-severity vulnerability involving Incorrect Control Flow Scoping. This was a conventional code flaw, not malware. The package's latest release (3.0.1) is clear, so developers can use it without concern from that past issue. Advisory history (1)
|
||||||||
| #790 | @protobufjs/utf8 | 1.1.2 | - | Clear | May 12, 2026 | 1 |
1
moderate
|
|
|
AI-generated context
@protobufjs/utf8 has one moderate advisory in its history, GHSA-q6x5-8v7m-xcrf, which concerned overlong UTF-8 decoding — a conventional vulnerability rather than malware. This issue has since been addressed, and the package's current release at version 1.1.2 is clear. Advisory history (1)
|
||||||||
| #791 | @protobufjs/codegen | 2.0.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #792 | rollup | 4.62.3 | - | Clear | Feb 25, 2026 | 2 |
2
high
|
|
|
AI-generated context
Rollup has accumulated two high-severity conventional vulnerability advisories in its history: GHSA-gcx4-mw62-g8wm involved a DOM Clobbering gadget in bundled scripts that could lead to cross-site scripting, and GHSA-mw96-cpmx-2vgc described an arbitrary file write vulnerability via path traversal in Rollup 4. Both issues have since been addressed, and the package's current release at version 4.62.2 is clear. Advisory history (2)
|
||||||||
| #793 | @radix-ui/number | 1.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #794 | @smithy/core | 3.31.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #795 | @types/qs | 6.15.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #796 | jest-environment-node | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #797 | @protobufjs/inquire | 1.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #798 | @babel/plugin-transform-modules-commonjs | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #799 | ansi-colors | 4.1.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #800 | jest-resolve | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #801 | @smithy/util-base64 | 4.5.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #802 | cssom | 0.5.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #803 | @smithy/credential-provider-imds | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #804 | ecdsa-sig-formatter | 1.0.11 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #805 | eslint-import-resolver-node | 0.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #806 | camelcase-css | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #807 | immer | 11.1.15 | - | Clear | Sep 07, 2021 | 3 |
1
critical
2
high
|
|
|
AI-generated context
The `immer` package has a history of conventional (non-malware) prototype pollution vulnerabilities, with three advisories published in 2021 — GHSA-9qmh-276g-x5pj (high), GHSA-33f9-j839-rf8h (critical), and GHSA-c36v-fmgq-m8hx (high) — all involving the same class of attack where an adversary could manipulate JavaScript object prototypes. These issues were addressed in past releases, and the package's current latest version is considered clear with no outstanding vulnerabilities. Advisory history (3)
|
||||||||
| #808 | victory-vendor | 37.3.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #809 | @smithy/middleware-serde | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #810 | @tailwindcss/node | 4.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #811 | @types/yargs-parser | 21.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #812 | @radix-ui/react-label | 2.1.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #813 | @babel/helper-optimise-call-expression | 8.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #814 | process | 0.11.10 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #815 | @aws-sdk/nested-clients | 3.997.37 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #816 | @smithy/url-parser | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #817 | fast-equals | 6.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #818 | @noble/hashes | 2.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #819 | jest-snapshot | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #820 | @tailwindcss/oxide | 4.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #821 | @smithy/middleware-stack | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #822 | cli-truncate | 6.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #823 | eslint-plugin-import | 2.32.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #824 | @testing-library/dom | 10.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #825 | webpack | 5.109.2 | - | Clear | Feb 05, 2026 | 4 |
1
critical
1
moderate
2
low
|
|
|
AI-generated context
Webpack has a history of conventional security vulnerabilities — no malware — spanning a critical cross-realm object access issue (GHSA-hc6q-2mpp-qw7j), a moderate DOM Clobbering XSS gadget in AutoPublicPathRuntimeModule (GHSA-4vvj-4cpr-p986), and two low-severity build-time SSRF vulnerabilities in the `buildHttp` HttpUriPlugin related to URL allow-list bypasses (GHSA-38r7-794h-5758, GHSA-8fgc-7cc6-rx7x). These issues have all been addressed in prior releases, and the current version 5.108.4 is clear of known advisories. Advisory history (4)
|
||||||||
| #826 | @csstools/css-tokenizer | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #827 | @smithy/util-retry | 4.5.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #828 | serialize-javascript | 7.0.7 | - | Clear | Mar 27, 2026 | 5 |
2
high
3
moderate
|
|
|
AI-generated context
The serialize-javascript package has a history of conventional security vulnerabilities — no malware — spanning cross-site scripting issues (GHSA-h9rv-jmmf-4pgx, GHSA-76p7-773f-r4q5), remote code execution flaws tied to insecure serialization and RegExp/Date handling (GHSA-hxcc-f52p-wc94, GHSA-5c6j-r48x-rmvq), and a denial-of-service weakness via crafted array-like objects (GHSA-qj8w-gfj5-8c6v). These vulnerabilities reflect the inherent complexity of safely serializing JavaScript for untrusted contexts and have been addressed across successive releases. The current version 7.0.7 is clear, making it safe to use as long as dependencies are kept up to date. Advisory history (5)
|
||||||||
| #829 | @smithy/service-error-classification | 4.5.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #830 | @types/react | 19.2.17 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #831 | @radix-ui/react-dropdown-menu | 2.1.24 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #832 | jest-docblock | 30.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #833 | sisteransi | 2.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #834 | @aws-sdk/credential-provider-ini | 3.973.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #835 | postcss-nested | 7.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #836 | @smithy/querystring-parser | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #837 | lie | 3.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #838 | @smithy/util-stream | 4.7.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #839 | @colors/colors | 1.6.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #840 | requires-port | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #841 | string-length | 7.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #842 | web-streams-polyfill | 4.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #843 | @radix-ui/react-tooltip | 1.2.16 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #844 | @smithy/node-config-provider | 4.5.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #845 | @octokit/openapi-types | 27.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #846 | diff-sequences | 29.6.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #847 | unist-util-visit | 5.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #848 | @smithy/util-uri-escape | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #849 | @types/istanbul-reports | 3.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #850 | tar-fs | 3.1.3 | - | Clear | Sep 24, 2025 | 4 |
4
high
|
|
|
AI-generated context
The tar-fs package has a recurring history of high-severity path traversal and link-following vulnerabilities, with advisories spanning from 2019 through 2025 (GHSA-x2mc-8fgj-3wmr, GHSA-pq67-2wwv-3xjx, GHSA-8cj5-5rvv-wf4v, and GHSA-vj76-c3g6-qr5v), all involving crafted tarballs that could extract files outside the intended destination directory. None of these were malware; they were conventional security flaws in how the library handled archive extraction. The current latest release, 3.1.3, is clear, but the pattern of recurring issues in this area is worth keeping in mind when planning upgrade and dependency monitoring strategies. Advisory history (4)
|
||||||||
| #851 | expect-type | 1.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #852 | is-buffer | 2.0.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #853 | @testing-library/jest-dom | 7.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #854 | @types/deep-eql | 4.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #855 | terser-webpack-plugin | 5.6.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #856 | unist-util-visit-parents | 6.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #857 | @tanstack/query-core | 5.101.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #858 | file-type | 22.0.1 | - | Clear | Mar 13, 2026 | 3 |
1
high
2
moderate
|
|
|
AI-generated context
The `file-type` package has a history of conventional denial-of-service vulnerabilities, with no malware involvement. These included an infinite loop triggered by malformed MKV files (GHSA-mhxj-85r3-2x55), a similar infinite loop in the ASF parser via zero-size sub-headers (GHSA-5v7r-6r5c-r473), and a ZIP decompression bomb attack through malformed `[Content_Types].xml` entries (GHSA-j47w-4g3g-c36v). The current release at version 22.0.1 is clear, so developers processing untrusted files can use it with confidence that these issues have been addressed. Advisory history (3)
|
||||||||
| #859 | watchpack | 2.5.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #860 | @radix-ui/react-separator | 1.1.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #861 | synckit | 0.11.13 | 0.11.9 | Clear | Jul 21, 2025 Malware incident · Jul 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
The package synckit was affected by two advisories in July 2025 (GHSA-f29h-pxvx-f335 and MAL-2025-6026) confirming the presence of malicious code embedded in a published version, alongside several other packages in the same supply chain incident. These were genuine malware findings, not conventional vulnerability disclosures. The latest release (0.11.13) is currently clear, meaning the malicious code has been addressed, but the incident serves as a reminder that this package was a target of a supply chain attack. Advisory history (2)
|
||||||||
| #862 | babel-preset-jest | 30.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #863 | @smithy/middleware-retry | 4.7.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #864 | @smithy/util-hex-encoding | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #865 | @radix-ui/react-menu | 2.1.24 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #866 | eslint-plugin-react | 7.37.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #867 | prompts | 2.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #868 | @types/body-parser | 1.19.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #869 | find-cache-dir | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #870 | unist-util-is | 6.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #871 | make-fetch-happen | 16.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #872 | chardet | 2.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #873 | jest-watcher | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #874 | core-js-compat | 3.49.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #875 | jws | 4.0.1 | 4.0.0 | Clear | Dec 04, 2025 | 2 |
2
high
|
|
|
AI-generated context
The `jws` package has two historical high-severity vulnerabilities in its past: GHSA-gjcw-v447-2w7q involved forgeable public/private tokens, and GHSA-869p-cjfg-cm3x concerned improper verification of HMAC signatures — both representing meaningful risks around JWT integrity if left unpatched. Neither advisory involves malware; they are conventional cryptographic implementation flaws. The current release (4.0.1) is clear, so developers on the latest version are not exposed to these issues. Advisory history (2)
|
||||||||
| #876 | stack-utils | 2.0.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #877 | is-obj | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #878 | @types/range-parser | 1.2.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #879 | @radix-ui/react-select | 2.3.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #880 | jest-runtime | 30.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #881 | @smithy/util-endpoints | 3.6.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #882 | inquirer | 14.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #883 | rfdc | 1.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #884 | unist-util-stringify-position | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #885 | import-local | 3.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #886 | @radix-ui/react-collapsible | 1.1.20 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #887 | through2 | 5.0.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #888 | @smithy/util-defaults-mode-node | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #889 | @radix-ui/react-popover | 1.1.23 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #890 | regjsparser | 0.13.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #891 | node-gyp | 13.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #892 | string.prototype.matchall | 4.0.12 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #893 | unplugin | 3.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #894 | micromark-util-symbol | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #895 | color | 5.0.3 | 5.0.1 | Clear | Sep 15, 2025 Malware incident · Sep 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
The `color` package was compromised in September 2025 when an npm account takeover led to the publication of malicious code in version 5.0.1, documented in both GHSA-qrmh-qg46-72pp and MAL-2025-46985. This was a supply chain attack involving malware injected into a specific release, rather than a conventional vulnerability in the package's own code. The package has since been remediated and the current release, version 5.0.3, is clear. Advisory history (2)
|
||||||||
| #896 | decimal.js-light | 2.5.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #897 | nwsapi | 2.2.24 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #898 | abort-controller | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #899 | spdx-expression-parse | 5.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #900 | @radix-ui/react-tabs | 1.1.21 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #901 | @protobufjs/eventemitter | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #902 | jest | 30.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #903 | @tanstack/react-query | 5.101.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #904 | jsonwebtoken | 9.0.3 | - | Clear | Dec 22, 2022 | 4 |
1
critical
1
high
2
moderate
|
|
|
AI-generated context
The jsonwebtoken package has a history of conventional security vulnerabilities — no malware — centered on JWT verification and cryptographic weaknesses, including a critical verification bypass (GHSA-c7hr-j4mj-j2w6) and a cluster of high and moderate severity issues in 2022 involving insecure default algorithms, unrestricted key types, and token forgery risks (GHSA-8cf7-32gw-wr33, GHSA-hjrf-2m68-5959, GHSA-qwph-4952-7xr6). These past vulnerabilities reflect meaningful risks that existed in older releases around authentication logic. The current latest release is clear, so developers on version 9.0.3 are not exposed to these historical issues. Advisory history (4)
|
||||||||
| #905 | @jest/reporters | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #906 | @protobufjs/fetch | 1.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #907 | tailwindcss | 4.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #908 | unique-filename | 6.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #909 | make-error | 1.3.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #910 | color-string | 2.1.4 | 2.1.1 | Clear | Sep 15, 2025 Malware incident · Sep 2025 | 3 |
1
high
1
moderate
1
malware
|
|
|
AI-generated context
The `color-string` package has had two distinct types of security issues in its history: a moderate Regular Expression Denial of Service vulnerability (GHSA-257v-vj4p-3w2h) reported in 2021, and more seriously, a temporary malware compromise in 2025 (MAL-2025-46973, GHSA-286p-vc9p-p5qv) when an npm account takeover resulted in a malicious version 2.1.1 being published. The malware-affected release has since been addressed, and the current latest version 2.1.4 is clear, so developers should ensure they are not pinned to any intermediate 2.1.x releases from that period. Advisory history (3)
|
||||||||
| #911 | @hookform/resolvers | 5.5.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #912 | glob-to-regexp | 0.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #913 | bluebird | 3.7.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #914 | @adobe/css-tools | 4.5.0 | - | Clear | Nov 30, 2023 | 2 |
2
moderate
|
|
|
AI-generated context
@adobe/css-tools has two historical advisories (GHSA-hpx4-r86g-5jrg and GHSA-prr3-c3m5-p7q2), both moderate severity, related to Regular Expression Denial of Service (ReDOS) and improper input validation when parsing CSS. These were conventional vulnerabilities with no malware involvement. The package is clear at its latest release, so developers depending on an up-to-date version are not affected by these past issues. Advisory history (2)
|
||||||||
| #915 | @tailwindcss/oxide-linux-x64-gnu | 4.3.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #916 | ts-node | 10.9.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #917 | @smithy/hash-node | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #918 | is-descriptor | 3.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #919 | @inquirer/type | 4.0.7 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #920 | psl | 1.15.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #921 | typescript-eslint | 8.65.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #922 | wordwrap | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #923 | jest-cli | 30.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #924 | @csstools/css-calc | 3.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #925 | resolve-cwd | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #926 | @types/json5 | 2.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #927 | @csstools/css-parser-algorithms | 4.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #928 | @jest/globals | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #929 | @protobufjs/aspromise | 1.1.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #930 | @img/sharp-linuxmusl-x64 | 0.35.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #931 | @radix-ui/react-progress | 1.1.16 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #932 | @jest/expect-utils | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #933 | fflate | 0.8.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #934 | get-package-type | 0.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #935 | @types/hast | 3.0.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #936 | jest-leak-detector | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #937 | @types/istanbul-lib-report | 3.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #938 | @babel/plugin-transform-classes | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #939 | @types/mdast | 4.0.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #940 | pathval | 2.0.1 | - | Clear | Feb 10, 2022 | 1 |
1
high
|
|
|
AI-generated context
The package has one historical advisory in its record, GHSA-g6ww-v8xp-vmwg, a high-severity prototype pollution vulnerability affecting an earlier version of pathval. This was a conventional security flaw rather than malware. The latest release (2.0.1) is clear, so developers depending on an up-to-date version of pathval are not affected by this past issue. Advisory history (1)
|
||||||||
| #941 | safe-stable-stringify | 2.5.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #942 | node-int64 | 0.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #943 | @radix-ui/react-toggle | 1.1.18 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #944 | @babel/helper-define-polyfill-provider | 1.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #945 | loupe | 3.2.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #946 | char-regex | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #947 | @babel/plugin-transform-block-scoping | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #948 | jest-runner | 30.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #949 | eslint-module-utils | 2.14.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #950 | decompress-response | 10.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #951 | uglify-js | 3.19.3 | - | Clear | Oct 24, 2017 | 2 |
1
critical
1
high
|
|
|
AI-generated context
Uglify-js has two historical advisories, both conventional vulnerabilities rather than malware: a critical issue (GHSA-34r7-q49f-h37c) involving incorrect handling of non-boolean comparisons during minification that could produce subtly broken output, and a high-severity regular expression denial of service (GHSA-c9f4-xj24-8jqx). Both were published in 2017 and have since been resolved, and the package's current release at version 3.19.3 is clear. Advisory history (2)
|
||||||||
| #952 | @smithy/util-defaults-mode-browser | 4.5.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #953 | @radix-ui/react-avatar | 1.2.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #954 | jest-circus | 30.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #955 | micromark-util-character | 2.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #956 | google-logging-utils | 1.2.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #957 | regexpu-core | 6.4.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #958 | lz-string | 1.5.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #959 | min-indent | 1.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #960 | @babel/plugin-syntax-numeric-separator | 7.10.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #961 | @babel/plugin-syntax-optional-catch-binding | 7.8.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #962 | fb-watchman | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #963 | bser | 2.1.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #964 | @babel/plugin-transform-spread | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #965 | deep-eql | 5.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #966 | @babel/plugin-syntax-top-level-await | 7.14.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #967 | @babel/plugin-syntax-nullish-coalescing-operator | 7.8.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #968 | zod-to-json-schema | 3.25.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #969 | progress | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #970 | @smithy/util-body-length-browser | 4.4.15 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #971 | @babel/plugin-transform-parameters | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #972 | @jest/source-map | 30.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #973 | immediate | 3.3.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #974 | @aws-sdk/client-sso | 3.1097.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #975 | @babel/plugin-syntax-object-rest-spread | 7.8.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #976 | normalize-url | 9.0.1 | - | Clear | Jun 08, 2021 | 1 |
1
high
|
|
|
AI-generated context
The package has one historical advisory in its record, GHSA-px4h-xg32-q955, a high-severity regular expression denial of service (ReDoS) vulnerability published in 2021. This was a conventional vulnerability, not malware, and it has since been addressed. The current release is clear, so developers depending on the latest version of normalize-url are not affected by this issue. Advisory history (1)
|
||||||||
| #977 | @smithy/config-resolver | 4.6.15 | - | Clear | Jan 08, 2026 | 1 |
1
low
|
|
|
AI-generated context
The package has one low-severity advisory in its history, GHSA-6475-r3vj-m8vf, which concerned a defense-in-depth enhancement to how the AWS SDK for JavaScript v3 handled region parameter values rather than any exploitable vulnerability. This was a conventional hardening improvement with no indication of malware. The current release is clear, making this a minimal-concern history for developers depending on the package today. Advisory history (1)
|
||||||||
| #978 | @babel/plugin-syntax-logical-assignment-operators | 7.10.4 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #979 | @protobufjs/pool | 1.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #980 | jest-changed-files | 30.4.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #981 | @babel/plugin-syntax-json-strings | 7.8.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #982 | @csstools/color-helpers | 6.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #983 | @types/lodash | 4.17.24 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #984 | webpack-virtual-modules | 0.6.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #985 | jest-resolve-dependencies | 30.4.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #986 | through | 2.3.8 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #987 | util | 0.12.5 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #988 | micromark-util-types | 2.0.2 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #989 | cacache | 21.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #990 | @types/stack-utils | 2.0.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #991 | @emnapi/wasi-threads | 2.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #992 | axobject-query | 4.1.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #993 | @pkgr/core | 0.3.6 | 0.2.8 | Clear | Jul 21, 2025 Malware incident · Jul 2025 | 2 |
1
high
1
malware
|
|
|
AI-generated context
@pkgr/core has two advisories in its history — GHSA-f29h-pxvx-f335 and MAL-2025-6021 — both related to malicious code having been embedded in the package, affecting it alongside several other tools in the same ecosystem. These were confirmed malware incidents rather than conventional vulnerabilities. The latest release (0.3.6) is currently clear, indicating the malicious code has been addressed, but developers should ensure they are not running any previously compromised versions. Advisory history (2)
|
||||||||
| #994 | @radix-ui/react-scroll-area | 1.2.18 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #995 | arrify | 3.0.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #996 | @babel/plugin-transform-computed-properties | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #997 | array.prototype.findlastindex | 1.2.6 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #998 | @opentelemetry/sdk-metrics | 2.10.0 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #999 | @babel/plugin-transform-for-of | 8.0.1 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||
| #1000 | @emnapi/core | 1.11.3 | - | Clear | - | 0 | - | |
|
No advisories for the latest published version. |
||||||||