Skip to content

fix(deps): update dependency firebase to ^11.10.0 - #10530

Merged
cryptodev-2s merged 2 commits into
mainfrom
renovate/firebase-firebase-js-sdk
Sep 28, 2026
Merged

cryptodev-2s merged 2 commits into
mainfrom
renovate/firebase-firebase-js-sdk

Conversation

@metamask-ci

@metamask-ci metamask-ci Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
firebase (source, changelog) ^11.2.0 → ^11.10.0 age confidence

Release Notes

firebase/firebase-js-sdk (firebase)

v11.10.0

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

firebase@​11.10.0

Minor Changes
  • 86155b3 #​9115 - Added support for Firestore result types to be serialized with toJSON and then deserialized with fromJSON methods on the objects.

Addeed support to resume onSnapshot listeners in the CSR phase based on serialized DataSnapshots and QuerySnapshots built in the SSR phase.

Patch Changes

@​firebase/firestore@4.8.0

Minor Changes
  • 86155b3 #​9115 - Added support for Firestore result types to be serialized with toJSON and then deserialized with fromJSON methods on the objects.

Addeed support to resume onSnapshot listeners in the CSR phase based on serialized DataSnapshots and QuerySnapshots built in the SSR phase.

Patch Changes

@​firebase/ai@1.4.1

Patch Changes

@​firebase/analytics@0.10.17

Patch Changes

@​firebase/analytics-compat@0.2.23

Patch Changes

@​firebase/app@0.13.2

Patch Changes

@​firebase/app-check@0.10.1

Patch Changes

@​firebase/app-check-compat@0.3.26

Patch Changes

@​firebase/app-compat@0.4.2

Patch Changes

@​firebase/auth@1.10.8

Patch Changes

@​firebase/auth-compat@0.5.28

Patch Changes

@​firebase/component@0.6.18

Patch Changes

@​firebase/data-connect@0.3.10

Patch Changes

@​firebase/database@1.0.20

Patch Changes

@​firebase/database-compat@2.0.11

Patch Changes

@​firebase/database-types@1.0.15

Patch Changes

@​firebase/firestore-compat@0.3.53

Patch Changes

@​firebase/functions@0.12.9

Patch Changes

@​firebase/functions-compat@0.3.26

Patch Changes

@​firebase/installations@0.6.18

Patch Changes

@​firebase/installations-compat@0.2.18

Patch Changes

@​firebase/messaging@0.12.22

Patch Changes

@​firebase/messaging-compat@0.2.22

Patch Changes

@​firebase/performance@0.7.7

Patch Changes

@​firebase/performance-compat@0.2.20

Patch Changes

@​firebase/remote-config@0.6.5

Patch Changes

@​firebase/remote-config-compat@0.2.18

Patch Changes

@​firebase/storage@0.13.14

Patch Changes

@​firebase/storage-compat@0.3.24

Patch Changes

@​firebase/util@1.12.1

Patch Changes
  • 42ac401 #​9111 - Fixed issue where Storage on Firebase Studio throws CORS errors.

v11.9.1

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

@​firebase/auth@1.10.7

Patch Changes
  • c0617a3 #​9075 - Fixed issue where Firebase Auth cookie refresh attempts issues in Firebase Studio resulted in CORS errors.

@​firebase/auth-compat@0.5.27

Patch Changes

firebase@​11.9.1

Patch Changes

@​firebase/storage@0.13.13

Patch Changes
  • 0f891d8 #​9059 - Fixed issue where Firebase Studio wasn't populating cookies for Storage users

@​firebase/storage-compat@0.3.23

Patch Changes

v11.9.0

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

@​firebase/ai@1.4.0

Minor Changes
  • 1933324 #​9026 - Add support for minItems and maxItems to Schema.

  • 40be2db #​9047 - Add title, maximum, minimum, propertyOrdering to Schema builder

firebase@​11.9.0

Minor Changes
  • 1933324 #​9026 - Add support for minItems and maxItems to Schema.

  • 40be2db #​9047 - Add title, maximum, minimum, propertyOrdering to Schema builder

Patch Changes

@​firebase/app@0.13.1

Patch Changes
  • Update SDK_VERSION.

@​firebase/app-compat@0.4.1

Patch Changes

@​firebase/firestore@4.7.17

Patch Changes
  • 9964849 #​9041 - Clean up leaked WebChannel instances when the Firestore instance is terminated.

@​firebase/firestore-compat@0.3.52

Patch Changes

v11.8.1

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

@​firebase/auth@1.10.6

Patch Changes

@​firebase/auth-compat@0.5.26

Patch Changes

@​firebase/data-connect@0.3.9

Patch Changes
  • b5df4ae #​9055 - Updated to only show banner when calling connect*Emulator

@​firebase/database@1.0.19

Patch Changes

@​firebase/database-compat@2.0.10

Patch Changes

firebase@​11.8.1

Patch Changes

@​firebase/firestore@4.7.16

Patch Changes

@​firebase/firestore-compat@0.3.51

Patch Changes

@​firebase/functions@0.12.8

Patch Changes

@​firebase/functions-compat@0.3.25

Patch Changes

@​firebase/storage@0.13.12

Patch Changes

@​firebase/storage-compat@0.3.22

Patch Changes

v11.8.0

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

Normal version packages workflow isn't working due to the app version bump step being hardcoded to main branch. Generated this manually using yarn changeset version which means no automatically formatted description.

This release is an out-of-band release from a temporary non-main branch.

firebase package version is:
11.7.3

See files for version changes of subpackages.

v11.7.3

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

Normal version packages workflow isn't working due to the app version bump step being hardcoded to main branch. Generated this manually using yarn changeset version which means no automatically formatted description.

This release is an out-of-band release from a temporary non-main branch.

firebase package version is:
11.7.3

See files for version changes of subpackages.

v11.7.2

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

Normal version packages workflow isn't working due to the app version bump step being hardcoded to main branch. Generated this manually using yarn changeset version which means no automatically formatted description.

This release is an out-of-band release from a temporary non-main branch.

firebase package version is 11.7.2

See files for version changes of subpackages.

v11.7.1

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

@​firebase/app@0.12.1

Patch Changes

@​firebase/app-check@0.9.1

Patch Changes

@​firebase/app-check-compat@0.3.22

Patch Changes

@​firebase/app-compat@0.3.1

Patch Changes

firebase@​11.7.1

Patch Changes

v11.7.0

Compare Source

For more detailed release notes, see Firebase JavaScript SDK Release Notes.

What's Changed

@​firebase/app@0.12.0

Minor Changes
  • 3789b5a #​8999 - Default automaticDataCollectionEnabled to true without changing App Check's default behavior.
Patch Changes

@​firebase/app-check@0.9.0

Minor Changes
  • 3789b5a #​8999 - Default automaticDataCollectionEnabled to true without changing App Check's default behavior.
Patch Changes

@​firebase/app-compat@0.3.0

Minor Changes
  • 3789b5a #​8999 - Default automaticDataCollectionEnabled to true without changing App Check's default behavior.
Patch Changes

firebase@​11.7.0

Minor Changes
  • 3789b5a #​8999 - Default automaticDataCollectionEnabled to true without changing App Check's default behavior.
Patch Changes

@​firebase/analytics@0.10.13

Patch Changes

@​firebase/analytics-compat@0.2.19

Patch Changes

@​firebase/app-check-compat@0.3.21

Patch Changes

@​firebase/auth@1.10.2

Patch Changes

@​firebase/auth-compat@0.5.22

Patch Changes

@​firebase/component@0.6.14

Patch Changes

@​firebase/data-connect@0.3.5

Patch Changes

@​firebase/database@1.0.15

Patch Changes

@​firebase/database-compat@2.0.6

Patch Changes

@​firebase/database-types@1.0.11

Patch Changes

@​firebase/firestore@4.7.12

Patch Changes

@​firebase/firestore-compat@0.3.47

Patch Changes

@​firebase/functions@0.12.4

Patch Changes

@​firebase/functions-compat@0.3.21

Patch Changes

[@​firebase/installations](https://redirect.github.com/firebase/installat

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.


Note

Medium Risk
Push delivery depends on Firebase Messaging; a multi-minor SDK jump can affect token lifecycle or SW behavior even without local code edits, so web/mobile push smoke tests are worthwhile.

Overview
Bumps the firebase dependency in @metamask/notification-services-controller from ^11.2.0 to ^11.10.0, with a matching Unreleased changelog entry and yarn.lock refresh across the @firebase/* tree (resolved firebase@11.10.0, including updated @firebase/messaging and related packages).

There are no source changes in this PR—only dependency and lockfile updates. Local usage stays on firebase/app and firebase/messaging (plus firebase/messaging/sw) for FCM token and push handling in the web push path.

Reviewed by Cursor Bugbot for commit 5bb5f29. Bugbot is set up for automated code reviews on this repo. Configure here.

@metamask-ci
metamask-ci Bot requested review from a team as code owners September 28, 2026 14:09
@metamask-ci
metamask-ci Bot deployed to default-branch September 28, 2026 14:10 Active
@metamask-ci
metamask-ci Bot deployed to dependabot September 28, 2026 14:10 Active
@socket-security

socket-security Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedfirebase@​11.2.0 ⏵ 11.10.080 +1100100 +198100

View full report

@socket-security

socket-security Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Warning

MetaMask internal reviewing guidelines:

  • Do not ignore-all
  • Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
  • Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe.
    @SocketSecurity ignore npm/PACKAGE@VERSION
Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
Network access: npm @firebase/ai in module globalThis["fetch"]

Module: globalThis["fetch"]

Location: Package overview

From: packages/notification-services-controller/package.json → npm/firebase@11.10.0 → npm/@firebase/ai@1.4.1

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@firebase/ai@1.4.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Install-time scripts: npm @firebase/util during postinstall

Install script: postinstall

Source: node ./postinstall.js

From: packages/notification-services-controller/package.json → npm/firebase@11.10.0 → npm/@firebase/util@1.12.1

ℹ Read more on: This package | This alert | What is an install script?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@firebase/util@1.12.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Medium
Network access: npm @firebase/util in module globalThis["fetch"]

Module: globalThis["fetch"]

Location: Package overview

From: packages/notification-services-controller/package.json → npm/firebase@11.10.0 → npm/@firebase/util@1.12.1

ℹ Read more on: This package | This alert | What is network access?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@firebase/util@1.12.1. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm @firebase/auth is 66.0% likely to have a medium risk anomaly

Notes: No clear evidence of intentional malware/backdoor behavior in the provided fragment. However, there are two high-impact security risks to review in supply-chain/sandbox terms: (1) an experimental auth token synchronization feature that can send Bearer id tokens to authTokenSyncURL via fetch (data exfiltration risk if that URL is attacker-controlled/misconfigured), and (2) dynamic external script loading through a pluggable externalJSProvider (arbitrary script execution risk only if the provider/URLs can be tampered with at runtime). Overall, this looks like a legitimate auth SDK codebase with standard behaviors plus a potentially dangerous optional token-sync capability.

Confidence: 0.66

Severity: 0.55

From: packages/notification-services-controller/package.json → npm/firebase@11.10.0 → npm/@firebase/auth@1.10.8

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/@firebase/auth@1.10.8. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn Low
Potential code anomaly (AI signal): npm firebase is 60.0% likely to have a medium risk anomaly

Notes: No definitive malware behavior is proven in the provided fragment; it largely resembles a Firebase client SDK bundle (auth flows, realtime listeners, persistence). However, it contains a high-suspicion capability: long-poll transport implemented via hidden iframe document writing and dynamically injected <script> tags pointing to runtime-computed network endpoints. This should be treated as a supply-chain security review hotspot—specifically verify host/endpoint allowlisting and ensure sensitive tokens are only transmitted to intended Firebase backends, with no untrusted inputs capable of influencing the destination.

Confidence: 0.60

Severity: 0.55

From: packages/notification-services-controller/package.json → npm/firebase@11.10.0

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/firebase@11.10.0. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@cryptodev-2s
cryptodev-2s added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit 858edfd Sep 28, 2026
44 checks passed
@cryptodev-2s
cryptodev-2s deleted the renovate/firebase-firebase-js-sdk branch September 28, 2026 17:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant