You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
fix(deps): update dependency firebase to ^11.10.0 - #10530
Normal version packages workflow isn't working due to the app version bump step being hardcoded to main branch. Generated this manually using yarn changeset version which means no automatically formatted description.
This release is an out-of-band release from a temporary non-main branch.
Normal version packages workflow isn't working due to the app version bump step being hardcoded to main branch. Generated this manually using yarn changeset version which means no automatically formatted description.
This release is an out-of-band release from a temporary non-main branch.
Normal version packages workflow isn't working due to the app version bump step being hardcoded to main branch. Generated this manually using yarn changeset version which means no automatically formatted description.
This release is an out-of-band release from a temporary non-main branch.
Medium Risk
Push delivery depends on Firebase Messaging; a multi-minor SDK jump can affect token lifecycle or SW behavior even without local code edits, so web/mobile push smoke tests are worthwhile.
Overview
Bumps the firebase dependency in @metamask/notification-services-controller from ^11.2.0 to ^11.10.0, with a matching Unreleased changelog entry and yarn.lock refresh across the @firebase/* tree (resolved firebase@11.10.0, including updated @firebase/messaging and related packages).
There are no source changes in this PR—only dependency and lockfile updates. Local usage stays on firebase/app and firebase/messaging (plus firebase/messaging/sw) for FCM token and push handling in the web push path.
Reviewed by Cursor Bugbot for commit 5bb5f29. Bugbot is set up for automated code reviews on this repo. Configure here.
Each alert has instructions on how to review if you don't know what it means. If lost, ask your Security Liaison or the supply-chain group
Copy-paste ignore lines for specific packages or a group of one kind with a note on what research you did to deem it safe. @SocketSecurity ignore npm/PACKAGE@VERSION
Action
Severity
Alert (click "▶" to expand/collapse)
Warn
Network access: npm @firebase/ai in module globalThis["fetch"]
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@firebase/ai@1.4.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Install-time scripts: npm @firebase/util during postinstall
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should not be running non-essential scripts during install and there are often solutions to problems people solve with install scripts that can be run at publish time instead.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@firebase/util@1.12.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Network access: npm @firebase/util in module globalThis["fetch"]
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: Packages should remove all network access that is functionally unnecessary. Consumers should audit network access to ensure legitimate use.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@firebase/util@1.12.1. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Potential code anomaly (AI signal): npm @firebase/auth is 66.0% likely to have a medium risk anomaly
Notes: No clear evidence of intentional malware/backdoor behavior in the provided fragment. However, there are two high-impact security risks to review in supply-chain/sandbox terms: (1) an experimental auth token synchronization feature that can send Bearer id tokens to authTokenSyncURL via fetch (data exfiltration risk if that URL is attacker-controlled/misconfigured), and (2) dynamic external script loading through a pluggable externalJSProvider (arbitrary script execution risk only if the provider/URLs can be tampered with at runtime). Overall, this looks like a legitimate auth SDK codebase with standard behaviors plus a potentially dangerous optional token-sync capability.
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/@firebase/auth@1.10.8. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
Warn
Potential code anomaly (AI signal): npm firebase is 60.0% likely to have a medium risk anomaly
Notes: No definitive malware behavior is proven in the provided fragment; it largely resembles a Firebase client SDK bundle (auth flows, realtime listeners, persistence). However, it contains a high-suspicion capability: long-poll transport implemented via hidden iframe document writing and dynamically injected <script> tags pointing to runtime-computed network endpoints. This should be treated as a supply-chain security review hotspot—specifically verify host/endpoint allowlisting and ensure sensitive tokens are only transmitted to intended Firebase backends, with no untrusted inputs capable of influencing the destination.
Next steps: Take a moment to review the security alert above. Review
the linked package source code to understand the potential risk. Ensure the
package is not malicious before proceeding. If you're unsure how to proceed,
reach out to your security team or ask the Socket team for help at
support@socket.dev.
Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.
Mark the package as acceptable risk. To ignore this alert only
in this pull request, reply with the comment
@SocketSecurity ignore npm/firebase@11.10.0. You can
also ignore all packages with @SocketSecurity ignore-all.
To ignore an alert for all future pull requests, use Socket's Dashboard to
change the triage state of this alert.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^11.2.0→^11.10.0Release Notes
firebase/firebase-js-sdk (firebase)
v11.10.0Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
firebase@11.10.0
Minor Changes
86155b3#9115 - Added support for Firestore result types to be serialized withtoJSONand then deserialized withfromJSONmethods on the objects.Addeed support to resume
onSnapshotlisteners in the CSR phase based on serializedDataSnapshots andQuerySnapshots built in the SSR phase.Patch Changes
13e6cce#9085 - Add rollup config to generate modular typings for google3Updated dependencies [
13e6cce,42ac401,bb57947,f73e08b,86155b3,b97eab3]:@firebase/remote-config@0.6.5
@firebase/analytics@0.10.17
@firebase/storage@0.13.14
@firebase/util@1.12.1
@firebase/app@0.13.2
@firebase/firestore@4.8.0
@firebase/ai@1.4.1
@firebase/remote-config-compat@0.2.18
@firebase/analytics-compat@0.2.23
@firebase/storage-compat@0.3.24
@firebase/app-check@0.10.1
@firebase/app-check-compat@0.3.26
@firebase/app-compat@0.4.2
@firebase/auth@1.10.8
@firebase/auth-compat@0.5.28
@firebase/data-connect@0.3.10
@firebase/database@1.0.20
@firebase/database-compat@2.0.11
@firebase/firestore-compat@0.3.53
@firebase/functions@0.12.9
@firebase/functions-compat@0.3.26
@firebase/installations@0.6.18
@firebase/installations-compat@0.2.18
@firebase/messaging@0.12.22
@firebase/messaging-compat@0.2.22
@firebase/performance@0.7.7
@firebase/performance-compat@0.2.20
@firebase/firestore@4.8.0
Minor Changes
86155b3#9115 - Added support for Firestore result types to be serialized withtoJSONand then deserialized withfromJSONmethods on the objects.Addeed support to resume
onSnapshotlisteners in the CSR phase based on serializedDataSnapshots andQuerySnapshots built in the SSR phase.Patch Changes
f73e08b#9087 - Internal listener registration change for IndexedDB "versionchange" events.Updated dependencies [
42ac401]:@firebase/util@1.12.1
@firebase/component@0.6.18
@firebase/ai@1.4.1
Patch Changes
b97eab3#9090 - Add deprecation label tototalBillableCharacters.totalTokensshould be used instead.Updated dependencies [
42ac401]:@firebase/util@1.12.1
@firebase/component@0.6.18
@firebase/analytics@0.10.17
Patch Changes
13e6cce#9085 - Add rollup config to generate modular typings for google3Updated dependencies [
42ac401]:@firebase/util@1.12.1
@firebase/component@0.6.18
@firebase/installations@0.6.18
@firebase/analytics-compat@0.2.23
Patch Changes
13e6cce,42ac401]:@firebase/app@0.13.2
Patch Changes
bb57947#9112 (fixes #8988) - Add "react-native" entry point to @firebase/appUpdated dependencies [
42ac401]:@firebase/util@1.12.1
@firebase/component@0.6.18
@firebase/app-check@0.10.1
Patch Changes
42ac401]:@firebase/app-check-compat@0.3.26
Patch Changes
42ac401]:@firebase/app-compat@0.4.2
Patch Changes
42ac401,bb57947]:@firebase/auth@1.10.8
Patch Changes
42ac401]:@firebase/auth-compat@0.5.28
Patch Changes
42ac401]:@firebase/component@0.6.18
Patch Changes
42ac401]:@firebase/data-connect@0.3.10
Patch Changes
42ac401]:@firebase/database@1.0.20
Patch Changes
42ac401]:@firebase/database-compat@2.0.11
Patch Changes
42ac401]:@firebase/database-types@1.0.15
Patch Changes
42ac401]:@firebase/firestore-compat@0.3.53
Patch Changes
42ac401,f73e08b,86155b3]:@firebase/functions@0.12.9
Patch Changes
42ac401]:@firebase/functions-compat@0.3.26
Patch Changes
42ac401]:@firebase/installations@0.6.18
Patch Changes
42ac401]:@firebase/installations-compat@0.2.18
Patch Changes
42ac401]:@firebase/messaging@0.12.22
Patch Changes
42ac401]:@firebase/messaging-compat@0.2.22
Patch Changes
42ac401]:@firebase/performance@0.7.7
Patch Changes
42ac401]:@firebase/performance-compat@0.2.20
Patch Changes
42ac401]:@firebase/remote-config@0.6.5
Patch Changes
13e6cce#9085 - Add rollup config to generate modular typings for google3Updated dependencies [
42ac401]:@firebase/util@1.12.1
@firebase/component@0.6.18
@firebase/installations@0.6.18
@firebase/remote-config-compat@0.2.18
Patch Changes
13e6cce,42ac401]:@firebase/storage@0.13.14
Patch Changes
42ac401#9111 - Fixed issue where Storage on Firebase Studio throws CORS errors.Updated dependencies [
42ac401]:@firebase/util@1.12.1
@firebase/component@0.6.18
@firebase/storage-compat@0.3.24
Patch Changes
42ac401]:@firebase/util@1.12.1
Patch Changes
42ac401#9111 - Fixed issue where Storage on Firebase Studio throws CORS errors.v11.9.1Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
@firebase/auth@1.10.7
Patch Changes
c0617a3#9075 - Fixed issue where Firebase Auth cookie refresh attempts issues in Firebase Studio resulted in CORS errors.@firebase/auth-compat@0.5.27
Patch Changes
c0617a3]:firebase@11.9.1
Patch Changes
0f891d8,c0617a3]:@firebase/storage@0.13.13
Patch Changes
0f891d8#9059 - Fixed issue where Firebase Studio wasn't populating cookies for Storage users@firebase/storage-compat@0.3.23
Patch Changes
0f891d8]:v11.9.0Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
@firebase/ai@1.4.0
Minor Changes
1933324#9026 - Add support forminItemsandmaxItemstoSchema.40be2db#9047 - Addtitle,maximum,minimum,propertyOrderingto Schema builderfirebase@11.9.0
Minor Changes
1933324#9026 - Add support forminItemsandmaxItemstoSchema.40be2db#9047 - Addtitle,maximum,minimum,propertyOrderingto Schema builderPatch Changes
1933324,9964849,40be2db]:@firebase/app@0.13.1
Patch Changes
@firebase/app-compat@0.4.1
Patch Changes
@firebase/firestore@4.7.17
Patch Changes
9964849#9041 - Clean up leaked WebChannel instances when the Firestore instance is terminated.@firebase/firestore-compat@0.3.52
Patch Changes
9964849]:v11.8.1Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
@firebase/auth@1.10.6
Patch Changes
35ad526#9053 - Revert "Fixed scroll behavior (#9043)"b5df4ae#9055 - Updated to only show banner when calling connect*Emulator@firebase/auth-compat@0.5.26
Patch Changes
35ad526,b5df4ae]:@firebase/data-connect@0.3.9
Patch Changes
b5df4ae#9055 - Updated to only show banner when calling connect*Emulator@firebase/database@1.0.19
Patch Changes
35ad526#9053 - Revert "Fixed scroll behavior (#9043)"b5df4ae#9055 - Updated to only show banner when calling connect*Emulator@firebase/database-compat@2.0.10
Patch Changes
35ad526,b5df4ae]:firebase@11.8.1
Patch Changes
35ad526,b5df4ae]:@firebase/firestore@4.7.16
Patch Changes
35ad526#9053 - Revert "Fixed scroll behavior (#9043)"b5df4ae#9055 - Updated to only show banner when calling connect*Emulator@firebase/firestore-compat@0.3.51
Patch Changes
35ad526,b5df4ae]:@firebase/functions@0.12.8
Patch Changes
35ad526#9053 - Revert "Fixed scroll behavior (#9043)"b5df4ae#9055 - Updated to only show banner when calling connect*Emulator@firebase/functions-compat@0.3.25
Patch Changes
35ad526,b5df4ae]:@firebase/storage@0.13.12
Patch Changes
35ad526#9053 - Revert "Fixed scroll behavior (#9043)"b5df4ae#9055 - Updated to only show banner when calling connect*Emulator@firebase/storage-compat@0.3.22
Patch Changes
35ad526,b5df4ae]:v11.8.0Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
Normal version packages workflow isn't working due to the app version bump step being hardcoded to
mainbranch. Generated this manually usingyarn changeset versionwhich means no automatically formatted description.This release is an out-of-band release from a temporary non-main branch.
firebasepackage version is:11.7.3
See files for version changes of subpackages.
v11.7.3Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
Normal version packages workflow isn't working due to the app version bump step being hardcoded to
mainbranch. Generated this manually usingyarn changeset versionwhich means no automatically formatted description.This release is an out-of-band release from a temporary non-main branch.
firebasepackage version is:11.7.3
See files for version changes of subpackages.
v11.7.2Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
Normal version packages workflow isn't working due to the app version bump step being hardcoded to
mainbranch. Generated this manually usingyarn changeset versionwhich means no automatically formatted description.This release is an out-of-band release from a temporary non-main branch.
firebasepackage version is 11.7.2See files for version changes of subpackages.
v11.7.1Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
@firebase/app@0.12.1
Patch Changes
51e7b48#9007 - Revert #8999@firebase/app-check@0.9.1
Patch Changes
51e7b48#9007 - Revert #8999@firebase/app-check-compat@0.3.22
Patch Changes
51e7b48]:@firebase/app-compat@0.3.1
Patch Changes
51e7b48#9007 - Revert #8999Updated dependencies [
51e7b48]:@firebase/app@0.12.1
firebase@11.7.1
Patch Changes
51e7b48]:v11.7.0Compare Source
For more detailed release notes, see Firebase JavaScript SDK Release Notes.
What's Changed
@firebase/app@0.12.0
Minor Changes
3789b5a#8999 - Default automaticDataCollectionEnabled to true without changing App Check's default behavior.Patch Changes
ea1f913,0e12766]:@firebase/app-check@0.9.0
Minor Changes
3789b5a#8999 - Default automaticDataCollectionEnabled to true without changing App Check's default behavior.Patch Changes
ea1f913,0e12766]:@firebase/app-compat@0.3.0
Minor Changes
3789b5a#8999 - Default automaticDataCollectionEnabled to true without changing App Check's default behavior.Patch Changes
3789b5a,ea1f913,0e12766]:firebase@11.7.0
Minor Changes
3789b5a#8999 - Default automaticDataCollectionEnabled to true without changing App Check's default behavior.Patch Changes
3789b5a,6a02778,ea1f913,0e12766]:@firebase/analytics@0.10.13
Patch Changes
ea1f913,0e12766]:@firebase/analytics-compat@0.2.19
Patch Changes
ea1f913,0e12766]:@firebase/app-check-compat@0.3.21
Patch Changes
3789b5a,ea1f913,0e12766]:@firebase/auth@1.10.2
Patch Changes
6a02778#8998 - Fix issue where auth port wasn't properly set when setting up cookies in Firebase Studio.0e12766#8968 - Fix Auth Redirects on Firebase StudioUpdated dependencies [
ea1f913,0e12766]:@firebase/util@1.11.1
@firebase/component@0.6.14
@firebase/auth-compat@0.5.22
Patch Changes
6a02778,ea1f913,0e12766]:@firebase/component@0.6.14
Patch Changes
ea1f913,0e12766]:@firebase/data-connect@0.3.5
Patch Changes
0e12766#8968 - Fix Auth Redirects on Firebase StudioUpdated dependencies [
ea1f913,0e12766]:@firebase/util@1.11.1
@firebase/component@0.6.14
@firebase/database@1.0.15
Patch Changes
ea1f913#8980 - Auto Enable SSL for Firebase Studio0e12766#8968 - Fix Auth Redirects on Firebase StudioUpdated dependencies [
ea1f913,0e12766]:@firebase/util@1.11.1
@firebase/component@0.6.14
@firebase/database-compat@2.0.6
Patch Changes
ea1f913#8980 - Auto Enable SSL for Firebase Studio0e12766#8968 - Fix Auth Redirects on Firebase StudioUpdated dependencies [
ea1f913,0e12766]:@firebase/database@1.0.15
@firebase/util@1.11.1
@firebase/component@0.6.14
@firebase/database-types@1.0.11
@firebase/database-types@1.0.11
Patch Changes
ea1f913,0e12766]:@firebase/firestore@4.7.12
Patch Changes
ea1f913#8980 - Auto Enable SSL for Firebase Studio0e12766#8968 - Fix Auth Redirects on Firebase StudioUpdated dependencies [
ea1f913,0e12766]:@firebase/util@1.11.1
@firebase/component@0.6.14
@firebase/firestore-compat@0.3.47
Patch Changes
ea1f913,0e12766]:@firebase/functions@0.12.4
Patch Changes
ea1f913#8980 - Auto Enable SSL for Firebase StudioUpdated dependencies [
ea1f913,0e12766]:@firebase/util@1.11.1
@firebase/component@0.6.14
@firebase/functions-compat@0.3.21
Patch Changes
ea1f913,0e12766]:[@firebase/installations](https://redirect.github.com/firebase/installat
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
Note
Medium Risk
Push delivery depends on Firebase Messaging; a multi-minor SDK jump can affect token lifecycle or SW behavior even without local code edits, so web/mobile push smoke tests are worthwhile.
Overview
Bumps the
firebasedependency in@metamask/notification-services-controllerfrom^11.2.0to^11.10.0, with a matching Unreleased changelog entry andyarn.lockrefresh across the@firebase/*tree (resolvedfirebase@11.10.0, including updated@firebase/messagingand related packages).There are no source changes in this PR—only dependency and lockfile updates. Local usage stays on
firebase/appandfirebase/messaging(plusfirebase/messaging/sw) for FCM token and push handling in the web push path.Reviewed by Cursor Bugbot for commit 5bb5f29. Bugbot is set up for automated code reviews on this repo. Configure here.