jlcvp / fcm-node

A Node.JS simple interface to Google's Firebase Cloud Messaging (FCM) for Android & iOS & Web Notification and data push
MIT License
125 stars 46 forks source link

[Snyk] Upgrade firebase-admin from 9.2.0 to 9.3.0 #71

Closed snyk-bot closed 3 years ago

snyk-bot commented 3 years ago

Snyk has created this PR to upgrade firebase-admin from 9.2.0 to 9.3.0.

merge advice :information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Prototype Pollution
SNYK-JS-GRPCGRPCJS-1038818
554/1000
Why? Proof of Concept exploit, Recently disclosed, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: firebase-admin
  • 9.3.0 - 2020-10-22

    Miscellaneous

    • [chore] Release 9.3.0 (#1070)
    • build(deps): bump @actions/core in /.github/actions/send-tweet (#1052)
    • Add support for Auth Emulator (#1044)
    • Update default.hbs (#1040)
  • 9.2.0 - 2020-09-15

    New Features

    • feat(ml): Adding Firebase ML support for AutoML models (#1024)

    Bug Fixes

    • fix(storage): Support typing generation for the storage API (#1019)

    Miscellaneous

    • [chore] Release 9.2.0 (#1030)
    • build(deps): bump node-forge from 0.9.1 to 0.10.0 (#1028)
    • Adding More ModelOptions to toc.yaml (#1027)
    • build(deps): bump node-fetch from 2.6.0 to 2.6.1 (#1025)
    • chore: Enabling max-len lint rule (#1014)
    • build(deps-dev): bump bcrypt from 3.0.8 to 5.0.0 (#1002)
    • Allow Credential to auto-generate typings, separate internal vs external APIs (#1012)
    • auth: Add credential service (#1011)
from firebase-admin GitHub release notes

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs