Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency firebase to v10 [SECURITY] #795

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 18, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
firebase (source, changelog) 9.19.1 -> 10.9.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-11023

Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.


Release Notes

firebase/firebase-js-sdk (firebase)

v10.9.0

Compare Source

v10.8.1

Compare Source

v10.8.0

Compare Source

v10.7.2

Compare Source

v10.7.1

Compare Source

v10.7.0

Compare Source

v10.6.0

Compare Source

v10.5.2

Compare Source

v10.5.1

Compare Source

v10.5.0

Compare Source

v10.4.0

Compare Source

v10.3.1

Compare Source

v10.3.0

Compare Source

v10.2.0

Compare Source

v10.1.0

Compare Source

v10.0.0

Compare Source

v9.23.0

Compare Source

v9.22.2

Compare Source

v9.22.1

Compare Source

v9.22.0

Compare Source

v9.21.0

Compare Source

v9.20.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

Automerge: Enabled

@renovate renovate bot enabled auto-merge (squash) November 18, 2024 23:19
Copy link

sonarcloud bot commented Nov 18, 2024

Copy link

Deploying newsdesk with  Cloudflare Pages  Cloudflare Pages

Latest commit: 05465e3
Status: ✅  Deploy successful!
Preview URL: https://764a1161.newsdesk.pages.dev
Branch Preview URL: https://renovate-npm-firebase-vulner.newsdesk.pages.dev

View logs

Copy link

cypress bot commented Nov 18, 2024

newsdesk    Run #2185

Run Properties:  status check passed Passed #2185  •  git commit a331688d15 ℹ️: Merge 05465e35b62245c269f5540ca811e34933700d9e into 214c13a5491d85e64bec1436dab5...
Project newsdesk
Branch Review refs/pull/795/merge
Run status status check passed Passed #2185
Run duration 02m 34s
Commit git commit a331688d15 ℹ️: Merge 05465e35b62245c269f5540ca811e34933700d9e into 214c13a5491d85e64bec1436dab5...
Committer renovate[bot]
View all properties for this run ↗︎

Test results
Tests that failed  Failures 0
Tests that were flaky  Flaky 0
Tests that did not run due to a developer annotating a test with .skip  Pending 1
Tests that did not run due to a failure in a mocha hook  Skipped 0
Tests that passed  Passing 24
View all changes introduced in this branch ↗︎

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants