firebase / firebase/firebase-admin-node

firebase-admin@14.2.0 stable dependency tree fails npm audit via Storage uuid and Firestore google-gax

未关闭
#3,221 3 条评论 0 个 reaction 已指派 1 人 已被 @lahirumaramba 认领 在 GitHub 查看
主要语言
TypeScript
星标
1.7k
派生
419
平均合并
3 天 10 小时
30 天内合并 PR
16

描述

## Summary

A Node 22 Functions package using the current stable `firebase-admin@14.2.0` cannot achieve a clean production `npm audit --omit=dev --audit-level=moderate` without overrides, forced downgrades, or prerelease dependencies.

## Reproduction

```bash
mkdir repro && cd repro
npm init -y
npm install --save-exact firebase-admin@14.2.0 firebase-functions@7.3.0
npm audit --omit=dev --audit-level=moderate
```

## Resolved stable paths

```text
firebase-admin@14.2.0
├─ @google-cloud/firestore@8.7.0
│ └─ google-gax@5.0.8
│ └─ rimraf@5.x -> glob@10.x -> minimatch -> brace-expansion@2.1.2
│ GHSA-mh99-v99m-4gvg (high)
└─ @google-cloud/storage@7.21.0
├─ gaxios@6.7.1 -> uuid@9.0.1
└─ retry-request@7.0.2 -> teeny-request@9.0.0 -> uuid@9.0.1
GHSA-w5hq-g745-h8pq (moderate)
```

`firebase-admin@14.2.0`, `@google-cloud/firestore@8.7.0`, `@google-cloud/storage@7.21.0`, and `google-gax@5.0.8` are the current stable npm `latest` versions at the time of this report. `npm update` produced no lockfile change. The audit suggested a breaking downgrade to `firebase-admin@10.3.0` for UUID, which is not a compatible mitigation.

Could Firebase Admin update its optional stable Firestore/Storage dependency chain once patched upstream releases are available, or publish guidance for a supported audit-clean resolution?

No Firebase project, credentials, tenant data, or production endpoint is involved in this report.

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。