Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

firebase-admin@14.2.0 stable dependency tree fails npm audit via Storage uuid and Firestore google-gax

Open
#3,221 3 comments 0 reactions 1 assignee View on GitHub

@lahirumaramba is already working on this.

Since Sep 8, 2026.

Assessment

This issue has not been assessed yet.

Description

Summary

A Node 22 Functions package using the current stable firebase-admin@14.2.0 cannot achieve a clean production npm audit --omit=dev --audit-level=moderate without overrides, forced downgrades, or prerelease dependencies.

Reproduction

mkdir repro && cd repro
npm init -y
npm install --save-exact firebase-admin@14.2.0 firebase-functions@7.3.0
npm audit --omit=dev --audit-level=moderate

Resolved stable paths

firebase-admin@14.2.0
├─ @google-cloud/firestore@8.7.0
│  └─ google-gax@5.0.8
│     └─ rimraf@5.x -> glob@10.x -> minimatch -> brace-expansion@2.1.2
│        GHSA-mh99-v99m-4gvg (high)
└─ @google-cloud/storage@7.21.0
   ├─ gaxios@6.7.1 -> uuid@9.0.1
   └─ retry-request@7.0.2 -> teeny-request@9.0.0 -> uuid@9.0.1
      GHSA-w5hq-g745-h8pq (moderate)

firebase-admin@14.2.0, @google-cloud/firestore@8.7.0, @google-cloud/storage@7.21.0, and google-gax@5.0.8 are the current stable npm latest versions at the time of this report. npm update produced no lockfile change. The audit suggested a breaking downgrade to firebase-admin@10.3.0 for UUID, which is not a compatible mitigation.

Could Firebase Admin update its optional stable Firestore/Storage dependency chain once patched upstream releases are available, or publish guidance for a supported audit-clean resolution?

No Firebase project, credentials, tenant data, or production endpoint is involved in this report.

Dominant language
TypeScript
Stars
1.7k
Forks
419
Avg merge
4d 20h
Merged PRs (30d)
16

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from firebase/firebase-admin-node

All issues in firebase/firebase-admin-node

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.