Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update dependency firebase-tools to v13.6.0 [security] #2031

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 3, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
firebase-tools 13.4.0 -> 13.6.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-4128

This vulnerability was a potential CSRF attack. When running the Firebase emulator suite, there is an export endpoint that is used normally to export data from running emulators. If a user was running the emulator and navigated to a malicious website with the exploit on a browser that allowed calls to localhost (ie Chrome before v94), the website could exfiltrate emulator data. We recommend upgrading past version 13.6.0 or commit 068a2b08dc308c7ab4b569617f5fc8821237e3a0.


Release Notes

firebase/firebase-tools (firebase-tools)

v13.6.0

Compare Source

  • Released Firestore Emulator 1.19.4. This version fixes a minor bug with reserve ids and adds a reset endpoint for Datastore Mode.
  • Released PubSub Emulator 0.8.2. This version includes support for no_wrapper options.
  • Fixes issue where GitHub actions service account cannot add preview URLs to Auth authorized domains. (#​6895)
  • Fixes issue where GOOGLE_CLOUD_QUOTA_PROJECT breaks functions source uploads (#​6917)

v13.5.2

Compare Source

  • Fix hosting rewrite deployment bug for skipped functions (#​6658).

v13.5.1

Compare Source

  • Release Emulator Suite UI v1.11.8 which adds support for Multiple DBs in the Emulator UI Firestore page via editing the URL. (#​6874)

v13.5.0

Compare Source

  • Enable dynamic debugger port for functions + support for inspecting multiple codebases (#​6854)
  • Inject an environment variable in the node functions emulator to tell the google-gax SDK not to look for the metadata service. (#​6860)
  • Release Firestore Emulator 1.19.3 which fixes ancestor and namespace scope queries for Datastore Mode. This release also fixes internal errors seen across REST API and firebase-js-sdk.
  • v2 scheduled functions with explicit service accounts trigger eventarc to use that service account (#​6858)
  • v2 event functions with explicit service accounts trigger eventarc to use that service account (#​6859)

v13.4.1

Compare Source

  • Released Firestore emulator v1.19.2, which fixes some bugs affecting client SDKs when in Datastore Mode.
  • Fix demo projects + web frameworks with emulators (#​6737)
  • Fix Next.js static routes with server actions (#​6664)
  • Fixed an issue where GOOGLE_CLOUD_QUOTA_PROJECT was not correctly respected. (#​6801)
  • Make VPC egress settings in functions parameterizeable (#​6843)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 5 times, most recently from e7a80be to dbb1157 Compare May 11, 2024 06:41
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 3 times, most recently from 21f2839 to 69428d1 Compare May 16, 2024 14:12
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch from 69428d1 to e68364c Compare May 21, 2024 19:55
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch from e68364c to 92fd0d0 Compare June 4, 2024 11:00
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 3 times, most recently from 6748277 to 12179ad Compare June 20, 2024 18:25
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 2 times, most recently from 79414b9 to 0b0f4ea Compare July 5, 2024 09:02
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch from 0b0f4ea to 203c7d7 Compare July 11, 2024 01:08
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch from 203c7d7 to a2deae4 Compare July 24, 2024 15:05
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch from a2deae4 to 7fb42e9 Compare August 6, 2024 17:37
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 7 times, most recently from fc999e6 to 2a2fc85 Compare August 24, 2024 07:34
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 5 times, most recently from 752b876 to 32676bb Compare August 29, 2024 19:20
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 10 times, most recently from ea934fb to 4bf3aa0 Compare September 21, 2024 19:42
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 4 times, most recently from 9d0dd1c to 9ea7670 Compare September 28, 2024 19:36
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 3 times, most recently from d8ac008 to 2114e7d Compare October 12, 2024 12:03
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 4 times, most recently from e2e67b7 to 6f636de Compare October 21, 2024 17:34
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch 7 times, most recently from 002a28f to 588c33e Compare October 28, 2024 18:41
@renovate renovate bot force-pushed the renovate/npm-firebase-tools-vulnerability branch from 588c33e to 9b5926a Compare November 5, 2024 19:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants