Update dependency firebase to v10 [SECURITY]#367
Update dependency firebase to v10 [SECURITY]#367renovate[bot] wants to merge 1 commit intomasterfrom
Conversation
609702d to
335f635
Compare
335f635 to
ea75556
Compare
|
Important Review skippedBot user detected. To trigger a single review, invoke the You can disable this status message by setting the 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
SupportNeed help? Join our Discord community for assistance with any issues or questions. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
|
Visit the preview URL for this PR (updated for commit ebf9194): https://coh2-ladders-dev--pr-367-hl0n5os5.web.app (expires Mon, 06 Apr 2026 17:39:33 GMT) 🔥 via Firebase Hosting GitHub Action 🌎 Sign: 1089e7820d4eb1cd4662591fc8ea563ca6528c79 |
ea75556 to
ebf9194
Compare
ebf9194 to
f1c6283
Compare
Renovate Ignore NotificationBecause you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR. |
This PR contains the following updates:
9.14.0→10.9.0GitHub Vulnerability Alerts
CVE-2024-11023
Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.
Release Notes
firebase/firebase-js-sdk (firebase)
v10.9.0Compare Source
v10.8.1Compare Source
v10.8.0Compare Source
v10.7.2Compare Source
v10.7.1Compare Source
v10.7.0Compare Source
v10.6.0Compare Source
v10.5.2Compare Source
v10.5.1Compare Source
v10.5.0Compare Source
v10.4.0Compare Source
v10.3.1Compare Source
v10.3.0Compare Source
v10.2.0Compare Source
v10.1.0Compare Source
v10.0.0Compare Source
v9.23.0Compare Source
v9.22.2Compare Source
v9.22.1Compare Source
v9.22.0Compare Source
v9.21.0Compare Source
v9.20.0Compare Source
v9.19.1Compare Source
v9.19.0Compare Source
v9.18.0Compare Source
v9.17.2Compare Source
v9.17.1Compare Source
v9.17.0Compare Source
v9.16.0Compare Source
v9.15.0Compare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.