Skip to content

firebase-admin@14.2.0 stable dependency tree fails npm audit via Storage uuid and Firestore google-gax #3221

Description

@roddysmith23-stack

Summary

A Node 22 Functions package using the current stable firebase-admin@14.2.0 cannot achieve a clean production npm audit --omit=dev --audit-level=moderate without overrides, forced downgrades, or prerelease dependencies.

Reproduction

mkdir repro && cd repro
npm init -y
npm install --save-exact firebase-admin@14.2.0 firebase-functions@7.3.0
npm audit --omit=dev --audit-level=moderate

Resolved stable paths

firebase-admin@14.2.0
├─ @google-cloud/firestore@8.7.0
│  └─ google-gax@5.0.8
│     └─ rimraf@5.x -> glob@10.x -> minimatch -> brace-expansion@2.1.2
│        GHSA-mh99-v99m-4gvg (high)
└─ @google-cloud/storage@7.21.0
   ├─ gaxios@6.7.1 -> uuid@9.0.1
   └─ retry-request@7.0.2 -> teeny-request@9.0.0 -> uuid@9.0.1
      GHSA-w5hq-g745-h8pq (moderate)

firebase-admin@14.2.0, @google-cloud/firestore@8.7.0, @google-cloud/storage@7.21.0, and google-gax@5.0.8 are the current stable npm latest versions at the time of this report. npm update produced no lockfile change. The audit suggested a breaking downgrade to firebase-admin@10.3.0 for UUID, which is not a compatible mitigation.

Could Firebase Admin update its optional stable Firestore/Storage dependency chain once patched upstream releases are available, or publish guidance for a supported audit-clean resolution?

No Firebase project, credentials, tenant data, or production endpoint is involved in this report.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions