Skip to content

[Snyk] Security upgrade firebase-admin from 9.11.0 to 11.4.1#141

Open
aravindvnair99 wants to merge 1 commit intomainfrom
snyk-fix-0a893e894c099c36d5f844dce2c41d29
Open

[Snyk] Security upgrade firebase-admin from 9.11.0 to 11.4.1#141
aravindvnair99 wants to merge 1 commit intomainfrom
snyk-fix-0a893e894c099c36d5f844dce2c41d29

Conversation

@aravindvnair99
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • functions/package.json
    • functions/package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 671/1000
Why? Recently disclosed, Has a fix available, CVSS 7.7
Improper Input Validation
SNYK-JS-JSONWEBTOKEN-3180020
Yes No Known Exploit
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Improper Authentication
SNYK-JS-JSONWEBTOKEN-3180022
Yes No Known Exploit
medium severity 611/1000
Why? Recently disclosed, Has a fix available, CVSS 6.5
Improper Restriction of Security Token Assignment
SNYK-JS-JSONWEBTOKEN-3180024
Yes No Known Exploit
medium severity 526/1000
Why? Recently disclosed, Has a fix available, CVSS 4.8
Use of a Broken or Risky Cryptographic Algorithm
SNYK-JS-JSONWEBTOKEN-3180026
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Use of a Broken or Risky Cryptographic Algorithm

@github-actions github-actions bot added the back-end Issues and pull requests related to back-end label Dec 23, 2022
@guardrails
Copy link

guardrails bot commented Dec 23, 2022

⚠️ We detected 25 security issues in this pull request:

Vulnerable Libraries (25)
Severity Details
High ansi-regex@5.0.0 (t) upgrade to: 5.0.0
High body-parser@1.19.0 (t) upgrade to: 1.19.0
Critical ejs@3.1.6 upgrade to: >=3.1.7
High express@4.17.1 (t) upgrade to: >4.17.2 || >5.0.0-alpha.8
High minimatch@3.0.4 (t) upgrade to: >=3.0.5
Low pkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
Low pkg:npm/node-fetch@2.6.7@2.6.7 (t) - no patch available
High pkg:npm/taffydb@2.6.2@2.6.2 (t) - no patch available
High pkg:npm/taffydb@2.6.2@2.6.2 (t) - no patch available
Critical pkg:npm/express@4.17.1@4.17.1 (t) - no patch available
Critical pkg:npm/express@4.17.1@4.17.1 (t) - no patch available
Critical pkg:npm/express@4.17.1@4.17.1 (t) - no patch available
Critical pkg:npm/express@4.17.1@4.17.1 (t) - no patch available
High pkg:npm/ansi-regex@5.0.0@5.0.0 (t) upgrade to: 6.0.1,5.0.1,4.1.1,3.0.1
High pkg:npm/ansi-regex@5.0.0@5.0.0 (t) upgrade to: 6.0.1,5.0.1,4.1.1,3.0.1
Critical pkg:npm/uglify-js@3.17.4@3.17.4 (t) - no patch available
Critical pkg:npm/uglify-js@3.17.4@3.17.4 (t) - no patch available
Critical pkg:npm/filelist@1.0.2@1.0.2 (t) - no patch available
Critical pkg:npm/filelist@1.0.2@1.0.2 (t) - no patch available
Critical pkg:npm/qs@6.7.0@6.7.0 (t) - no patch available
Critical pkg:npm/qs@6.7.0@6.7.0 (t) - no patch available
High pkg:npm/minimatch@3.0.4@3.0.4 (t) upgrade to: 3.0.5
High pkg:npm/minimatch@3.0.4@3.0.4 (t) upgrade to: 3.0.5
High pkg:npm/jake@10.8.2@10.8.2 (t) - no patch available
High pkg:npm/jake@10.8.2@10.8.2 (t) - no patch available

More info on how to fix Vulnerable Libraries in JavaScript.


👉 Go to the dashboard for detailed results.

📥 Happy? Share your feedback with us.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

back-end Issues and pull requests related to back-end size/XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants