Skip to content

Conversation

@Pittimon
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 823/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 8.6
Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
Yes Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: firebase-tools The new version differs by 250 commits.
  • 7d2a90e 12.4.5
  • 15b9cd9 Updating proxy-agent (#6160)
  • ad4e144 Next.js image optimization fixes (#6143)
  • 1f5f2ac Patch fix for issues caused by adding type check in #5906 (#6127)
  • 83c5292 Better message for api enablement failures (#6130)
  • 501c056 b/390633880 fix --only in firestore deploy (#6129)
  • 177a5c2 Fix issue where Flutter Web is not detected as a web framework (#6140)
  • b41c6f4 Improve error message when functions:shell command fails due to missing project association. (#6088)
  • 53b65d6 VSCode plugin: Disable Google login flow in monospace environment (#6131)
  • 5d6634e VSCode Plugin: Better error handling for init and deploy (#6124)
  • bd73173 Prune old versions when creating new secret version using `secrets:set` command (#6080)
  • 0586de7 [firebase-release] Removed change log and reset repo after 12.4.4 release
  • 337179b 12.4.4
  • 7b18626 Disabling flaky test on windows (#6122)
  • 1e4d802 Better logging to help debug login issues (#6119)
  • 473deff Fix requireAuthWrapper logic and service account email detection (#6115)
  • 6b27c62 fix spelling errors in functions (#6087)
  • a20cd4e Round of dependabot updates (#6116)
  • f458180 VSCode plugin: Add UX improvements (#6091)
  • c37634a Rewrite `src/localFunction.js` in TypeScript. (#6092)
  • 2a30b5d Clarifying what the CLI does with dynamic content on next.js (per customer feedback). (#6093)
  • eab7913 Make firebase:database:list to always use the RTDB management API (#6063)
  • 7a9d6f2 Disables KeepAlive timeout when debugger is attached to the functions emulator (#6069)
  • 3bcc671 VSCode plugin: Handle service accounts better (#6078)

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Server-side Request Forgery (SSRF)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants