Summary
A Node 22 Functions package using the current stable firebase-admin@14.2.0 cannot achieve a clean production npm audit --omit=dev --audit-level=moderate without overrides, forced downgrades, or prerelease dependencies.
Reproduction
mkdir repro && cd repro
npm init -y
npm install --save-exact firebase-admin@14.2.0 firebase-functions@7.3.0
npm audit --omit=dev --audit-level=moderate
Resolved stable paths
firebase-admin@14.2.0
├─ @google-cloud/firestore@8.7.0
│ └─ google-gax@5.0.8
│ └─ rimraf@5.x -> glob@10.x -> minimatch -> brace-expansion@2.1.2
│ GHSA-mh99-v99m-4gvg (high)
└─ @google-cloud/storage@7.21.0
├─ gaxios@6.7.1 -> uuid@9.0.1
└─ retry-request@7.0.2 -> teeny-request@9.0.0 -> uuid@9.0.1
GHSA-w5hq-g745-h8pq (moderate)
firebase-admin@14.2.0, @google-cloud/firestore@8.7.0, @google-cloud/storage@7.21.0, and google-gax@5.0.8 are the current stable npm latest versions at the time of this report. npm update produced no lockfile change. The audit suggested a breaking downgrade to firebase-admin@10.3.0 for UUID, which is not a compatible mitigation.
Could Firebase Admin update its optional stable Firestore/Storage dependency chain once patched upstream releases are available, or publish guidance for a supported audit-clean resolution?
No Firebase project, credentials, tenant data, or production endpoint is involved in this report.
Summary
A Node 22 Functions package using the current stable
firebase-admin@14.2.0cannot achieve a clean productionnpm audit --omit=dev --audit-level=moderatewithout overrides, forced downgrades, or prerelease dependencies.Reproduction
Resolved stable paths
firebase-admin@14.2.0,@google-cloud/firestore@8.7.0,@google-cloud/storage@7.21.0, andgoogle-gax@5.0.8are the current stable npmlatestversions at the time of this report.npm updateproduced no lockfile change. The audit suggested a breaking downgrade tofirebase-admin@10.3.0for UUID, which is not a compatible mitigation.Could Firebase Admin update its optional stable Firestore/Storage dependency chain once patched upstream releases are available, or publish guidance for a supported audit-clean resolution?
No Firebase project, credentials, tenant data, or production endpoint is involved in this report.