Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Upgrade firebase-functions from 3.6.0 to 3.15.4 #12

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

snyk-bot
Copy link

Snyk has created this PR to upgrade firebase-functions from 3.6.0 to 3.15.4.

merge advice
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 20 versions ahead of your current version.
  • The recommended version was released 25 days ago, on 2021-08-16.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-LODASH-590103
490/1000
Why? CVSS 9.8
No Known Exploit
Command Injection
SNYK-JS-LODASH-1040724
490/1000
Why? CVSS 9.8
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
490/1000
Why? CVSS 9.8
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: firebase-functions
  • 3.15.4 - 2021-08-16
    • Fix bug where the arg of https onCall functions sometimes deviates from the documented format.
  • 3.15.3 - 2021-08-13
    • (temporarly) adds the previously accessible "lib/providers" files as exports. These will be yanked in the next major release.
    • Fixes a bug where functions.https.HttpsError could not be constructed
  • 3.15.2 - 2021-08-12
    • Fix an error that broke firebase emulators:start on older CLIs
  • 3.15.1 - 2021-08-11
    • Fix bug that broke the functions emulator
  • 3.15.0 - 2021-08-11
    • Adds options to set access control on HTTP triggered functions.
    • Adds new regions to support list (asia-east1, asia-southeast1).
    • Adds support for setting user labels on functions via runWith().
    • Adds support for FIREBASE_CONFIG env as the name of a JSON file
    • Fixes an issue where objects that define toJSON could not be logged successfully (#907).
    • Formalize module exports. Loggers can now be accessed at 'firebase-functions/logger' and 'firebase-functions/logger/compat'
    • Fixes an issue where Remote Config could not be emulated in Windows machines on the classic Command Prompt.
  • 3.14.1 - 2021-05-17
    • Fixes a bug where typescript would fail to compile with old (but supported) versions of firebase-admin
    • Replaces 3.13.3 which was an inappropriately numbered version
  • 3.14.0 - 2021-05-12
    • Functions may now be deployed with 8GB RAM
    • Functions may now be deployed to europe-central2 (Warsaw)
    • Add support for validating App Check tokens for Callable Functions
  • 3.13.3 - 2021-05-17
    • Fixes a bug where typescript would fail to compile with old (but supported) versions of firebase-admin
  • 3.13.2 - 2021-02-22
    • Fixes issue where DATABASE_URL and STORAGE_BUCKET_URL could not be set to undefined. (#829)
    • Fixes a bug where ingressSettings could not be set. (#827)
  • 3.13.1 - 2021-01-15
    • Fixes a bug that prevented Functions from being deployed with availableMemoryMb set to 4GB.
    • Fixes bug where functions.logger.log crashes function if circular dependencies are passed in
  • 3.13.0 - 2020-12-07
  • 3.12.0 - 2020-11-30
  • 3.11.0 - 2020-08-21
  • 3.10.0 - 2020-08-20
  • 3.9.1 - 2020-08-12
  • 3.9.0 - 2020-07-31
  • 3.8.0 - 2020-07-14
  • 3.7.0 - 2020-06-09
  • 3.6.2 - 2020-05-28
  • 3.6.1 - 2020-04-24
  • 3.6.0 - 2020-03-31
from firebase-functions GitHub release notes
Commit messages
Package name: firebase-functions

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant