firebase / firebase/firebase-admin-node

firebase-admin@14.2.0 stable dependency tree fails npm audit via Storage uuid and Firestore google-gax

Offen
#3,221 3 Kommentare 0 Reaktionen 1 zugewiesene Person Beansprucht von @lahirumaramba Auf GitHub ansehen
Vorherrschende Sprache
TypeScript
Sterne
1.7k
Forks
419
Ø Merge
3 T. 10 Std.
Gemergte PRs (30 T.)
16

Beschreibung

## Summary

A Node 22 Functions package using the current stable `firebase-admin@14.2.0` cannot achieve a clean production `npm audit --omit=dev --audit-level=moderate` without overrides, forced downgrades, or prerelease dependencies.

## Reproduction

```bash
mkdir repro && cd repro
npm init -y
npm install --save-exact firebase-admin@14.2.0 firebase-functions@7.3.0
npm audit --omit=dev --audit-level=moderate
```

## Resolved stable paths

```text
firebase-admin@14.2.0
├─ @google-cloud/firestore@8.7.0
│ └─ google-gax@5.0.8
│ └─ rimraf@5.x -> glob@10.x -> minimatch -> brace-expansion@2.1.2
│ GHSA-mh99-v99m-4gvg (high)
└─ @google-cloud/storage@7.21.0
├─ gaxios@6.7.1 -> uuid@9.0.1
└─ retry-request@7.0.2 -> teeny-request@9.0.0 -> uuid@9.0.1
GHSA-w5hq-g745-h8pq (moderate)
```

`firebase-admin@14.2.0`, `@google-cloud/firestore@8.7.0`, `@google-cloud/storage@7.21.0`, and `google-gax@5.0.8` are the current stable npm `latest` versions at the time of this report. `npm update` produced no lockfile change. The audit suggested a breaking downgrade to `firebase-admin@10.3.0` for UUID, which is not a compatible mitigation.

Could Firebase Admin update its optional stable Firestore/Storage dependency chain once patched upstream releases are available, or publish guidance for a supported audit-clean resolution?

No Firebase project, credentials, tenant data, or production endpoint is involved in this report.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.