hirokisakabe / tascal-old

Simple todo list app
https://tascal.vercel.app
MIT License
0 stars 0 forks source link

Update dependency firebase to v10 [SECURITY] #157

Open renovate[bot] opened 22 hours ago

renovate[bot] commented 22 hours ago

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
firebase (source, changelog) 9.23.0 -> 10.9.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2024-11023

Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.


Release Notes

firebase/firebase-js-sdk (firebase) ### [`v10.9.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.8.1...firebase@10.9.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.8.1...firebase@10.9.0) ### [`v10.8.1`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.8.0...firebase@10.8.1) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.8.0...firebase@10.8.1) ### [`v10.8.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.7.2...firebase@10.8.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.7.2...firebase@10.8.0) ### [`v10.7.2`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.7.1...firebase@10.7.2) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.7.1...firebase@10.7.2) ### [`v10.7.1`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.7.0...firebase@10.7.1) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.7.0...firebase@10.7.1) ### [`v10.7.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.6.0...firebase@10.7.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.6.0...firebase@10.7.0) ### [`v10.6.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.5.2...firebase@10.6.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.5.2...firebase@10.6.0) ### [`v10.5.2`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.5.1...firebase@10.5.2) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.5.1...firebase@10.5.2) ### [`v10.5.1`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.5.0...firebase@10.5.1) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.5.0...firebase@10.5.1) ### [`v10.5.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.4.0...firebase@10.5.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.4.0...firebase@10.5.0) ### [`v10.4.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.3.1...firebase@10.4.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.3.1...firebase@10.4.0) ### [`v10.3.1`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.3.0...firebase@10.3.1) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.3.0...firebase@10.3.1) ### [`v10.3.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.2.0...firebase@10.3.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.2.0...firebase@10.3.0) ### [`v10.2.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.1.0...firebase@10.2.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.1.0...firebase@10.2.0) ### [`v10.1.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.0.0...firebase@10.1.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@10.0.0...firebase@10.1.0) ### [`v10.0.0`](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@9.23.0...firebase@10.0.0) [Compare Source](https://redirect.github.com/firebase/firebase-js-sdk/compare/firebase@9.23.0...firebase@10.0.0)

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR was generated by Mend Renovate. View the repository job log.