steadyequipment / node-firestore-backup

Google Firebase Firestore backup tool
190 stars 51 forks source link

Follow up and update firebase-admin once hoek dependancies updated to >= 5.0.3 #34

Open yoiang opened 6 years ago

yoiang commented 6 years ago

hoek versions < 5.0.3 have a potential Prototype pollution vulnerability. firebase-admin is our base dependency that eventually includes hoek.

firebase-admin: https://github.com/firebase/firebase-admin-node/issues/217 ~grpc-node:~ ~https://github.com/grpc/grpc-node/issues/225~ ~https://github.com/grpc/grpc-node/pull/311~ ~node-pre-gyp: https://github.com/mapbox/node-pre-gyp/issues/356~