Skip to content
This repository has been archived by the owner on Apr 20, 2023. It is now read-only.

[Snyk] Upgrade firebase from 9.19.1 to 9.20.0 #301

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade firebase from 9.19.1 to 9.20.0.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 10 versions ahead of your current version.
  • The recommended version was released a day ago, on 2023-04-18.
Release notes
Package name: firebase
  • 9.20.0 - 2023-04-18

    Co-authored-by: github-actions[bot] <github-actions[bot]@ users.noreply.github.com>

  • 9.20.0-canary.98abcd5ed - 2023-04-19
  • 9.20.0-canary.6f9d7b1db - 2023-04-19
  • 9.20.0-canary.68b79e1a0 - 2023-04-19
  • 9.20.0-canary.41f06beab - 2023-04-19
  • 9.20.0-canary.2d141ed9d - 2023-04-18
  • 9.20.0-canary.253b998fc - 2023-04-18
  • 9.20.0-canary.195e82ebb - 2023-04-18
  • 9.20.0-canary.0a27d2fbf - 2023-04-18
  • 9.20.0-20230413163153 - 2023-04-13
  • 9.19.1 - 2023-03-31

    Co-authored-by: github-actions[bot] <github-actions[bot]@ users.noreply.github.com>

from firebase GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

@socket-security
Copy link

New dependency changes detected. Learn more about Socket for GitHub ↗︎


🚨 Potential security issues found in this pull request. To accept the risk, merge this PR and you will not be notified again.

Bot Commands

To ignore an alert, reply with a comment starting with @SocketSecurity ignore followed by a space separated list of package-name@version specifiers. e.g. @SocketSecurity ignore foo@1.0.0 bar@* or ignore all packages with @SocketSecurity ignore-all

  • @SocketSecurity ignore protobufjs@6.11.3
📜 Install scripts

Install scripts are run when the package is installed. The majority of malware in npm is hidden in install scripts.

Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Package Script field Source
protobufjs@6.11.3 (added) postinstall package-lock.json via firebase@9.20.0
Pull request alert summary
Issue Status
Install scripts ⚠️ 1 issue
Native code ✅ 0 issues
Bin script shell injection ✅ 0 issues
Unresolved require ✅ 0 issues
Invalid package.json ✅ 0 issues
HTTP dependency ✅ 0 issues
Git dependency ✅ 0 issues
Potential typo squat ✅ 0 issues
Known Malware ✅ 0 issues
Telemetry ✅ 0 issues
Protestware/Troll package ✅ 0 issues

📊 Modified Dependency Overview:

➕ Added Package Capability Access +/- Transitive Count Publisher
firebase@9.20.0 network, environment +64 google-wombot

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
1 participant