Skip to content

chore(deps): bump stream-json from 1.9.1 to 3.7.0 in /examples/firebase-functions in the npm_and_yarn group across 1 directory - #228

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/examples/firebase-functions/npm_and_yarn-8bc1e7845a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/examples/firebase-functions/npm_and_yarn-8bc1e7845a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the npm_and_yarn group with 1 update in the /examples/firebase-functions directory: stream-json.

Updates stream-json from 1.9.1 to 3.7.0

Commits
  • ac4a46d New version: 3.7.0.
  • ca2bb67 Removed dead code.
  • c06c9a3 Perf optimization.
  • 1929fd8 Added depth capping for DoS hardening.
  • 9e35c67 Bump the npm-deps group with 2 updates (#222)
  • 945c62f Bump @​types/node from 26.4.0 to 26.5.0 in the npm-deps group (#221)
  • 77a4946 New version: 3.6.0.
  • 0291333 Added simplified replacement + fast check tests.
  • 0c816ae Bump @​types/node from 26.2.0 to 26.3.0 in the npm-deps group (#219)
  • c0299dc Reworked how comments are handled in JSONC.
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the npm_and_yarn group with 1 update in the /examples/firebase-functions directory: [stream-json](https://github.com/uhop/stream-json).


Updates `stream-json` from 1.9.1 to 3.7.0
- [Commits](uhop/stream-json@1.9.1...3.7.0)

---
updated-dependencies:
- dependency-name: stream-json
  dependency-version: 3.7.0
  dependency-type: indirect
  dependency-group: npm_and_yarn
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 28, 2026
@arcjet-review arcjet-review Bot added needs review Awaiting human review and removed needs review Awaiting human review labels Sep 28, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​firebase-tools@​15.30.1 ⏵ 15.32.086100100 +199 +1100

View full report

@socket-security

Copy link
Copy Markdown

Caution

Review the following alerts detected in dependencies.

According to your organization's Security Policy, you must resolve all "Block" alerts before proceeding. Learn more about Socket for GitHub.

Priority Alert  (click "▶" to expand/collapse) Action
Low priority
Potential vulnerability: npm firebase-tools with risk level "medium"

Location: Package overview

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | Navigating potential vulnerabilities

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: It is advisable to proceed with caution. Engage in a review of the package's security aspects and consider reaching out to the package maintainer for the latest information or patches.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential security risk (AI signal): npm firebase-tools is 62.0% likely risky

Notes: No direct evidence of stealthy malware (no network/exfiltration/persistence/file tampering observed in this snippet). However, the module is security-sensitive because it can execute an executable specified by process.argv[2] and then executes a derived binary path taken from JSON output without validation/allowlisting. If an attacker can influence argv[2] or the executed tool’s output in the environment, this can become arbitrary command execution in the context of the user. Additionally, unhandled JSON.parse failures introduce reliability/DoS risk, and terminal output derived from child stderr could carry terminal control-sequence risk.

Confidence: 0.62

Severity: 0.70

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential security risk (AI signal): npm firebase-tools is 65.0% likely risky

Notes: No explicit malware or exfiltration behavior is visible in this snippet, but the module is a powerful local execution driver. It can execute arbitrary OS commands from caller-controlled spec fields and can execute dynamically generated JavaScript via node -e based on hook-related inputs. If any upstream supply-chain inputs (spec/bundle/hook or the hook generator) are attacker-controlled, this becomes an effective arbitrary code execution vector with high security risk. Review and harden trust boundaries around spec, genHookScript, and the integrity of hooks_1.BUNDLE_PATH before parsing.

Confidence: 0.65

Severity: 0.72

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What are AI-detected potential security risks?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system identified potential security problems in this package. It is advised to review the package thoroughly and assess the potential risks before installation. You may also consider reporting the issue to the package maintainer or seeking alternative solutions with a stronger security posture.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 62.0% likely to have a medium risk anomaly

Notes: No clear evidence of intentional malware in this fragment. The dominant security risks are: (1) a blocking-function JWT generated with algorithm "none" (no integrity protection), and (2) potential forwarding of OAuth tokens to a configured remote blocking function URL, with remote JSON response driving account updates. These behaviors are high-impact if misused outside a strictly trusted emulator context, but they appear consistent with emulator/testing functionality in this snippet.

Confidence: 0.62

Severity: 0.52

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 66.0% likely to have a medium risk anomaly

Notes: No clear overt malware/backdoor behavior is visible in this module. The dominant security concern is high-impact handling of a sensitive credential: it reads GEMINI_API_KEY from a local .env and uploads it to a remote Firebase App Hosting secrets store. Additionally, it installs external agent skill packages (supply-chain exposure) and may spawn a locally resolved Antigravity executable (with extra execution-mode risk on Windows due to shell: true). These behaviors should be guarded with explicit consent, least privilege, and supply-chain verification controls in the broader implementation.

Confidence: 0.66

Severity: 0.68

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 64.0% likely to have a medium risk anomaly

Notes: This module is primarily an orchestration layer for downloading/building Firebase Extensions and wiring them into an emulator. It does not show explicit malware behaviors (no exfiltration/backdoors/dynamic code generation), but it performs high-impact supply-chain execution by running 'npm install' and 'npm run gcp-build' from downloaded or local extension code directories. Because the module only checks for file presence and does not show integrity verification or sandboxing before executing npm scripts, a compromised extension source/URI/ref or a tampered cache directory could lead to arbitrary code execution in the host emulator process.

Confidence: 0.64

Severity: 0.67

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 60.0% likely to have a medium risk anomaly

Notes: This fragment is a functional task dispatcher with retry/backoff and rate limiting. It does not show overt malware behavior (no eval/dynamic execution, no persistence, no system compromise). The dominant security concern is that it sends HTTP POST requests to task-supplied URLs and forwards task-supplied headers/body largely without validation or allowlisting; if an attacker can influence queued tasks, the code can be abused for SSRF/open egress and data exfiltration. Logging of raw error strings may additionally leak operational details.

Confidence: 0.60

Severity: 0.52

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 65.0% likely to have a medium risk anomaly

Notes: No strong evidence of intentional supply-chain malware (e.g., payload execution, backdoors, or external exfiltration) is present in this module. However, it introduces significant security risks: (1) protocol/database trust authentication (auth.method='trust') combined with network-reachable protocol execution via db.execProtocolRaw(data), making unauthorized SQL/commands possible if the TCP server is not tightly isolated; (2) unconditional persistent logging of decoded request/response protocol content to pglite-debug.log, which may leak sensitive SQL/data to disk; and (3) direct use of caller-controlled filesystem paths in fs reads/writes and recursive directory operations without visible validation, which can lead to path-related integrity risks. Security posture should rely on strict network binding/firewalling and path input validation outside this module.

Confidence: 0.65

Severity: 0.62

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 60.0% likely to have a medium risk anomaly

Notes: No explicit malware/backdoor behavior is evident in this module. However, it exposes highly privileged emulator administration capabilities (exporting emulator data to a request-provided path, disabling/reloading function triggers, and clearing Dataconnect data) via HTTP endpoints. Access control appears weak/inverted for some routes by using only the presence of the Origin header as a gate, and the request body’s export path/targets are forwarded without validation in this layer. The locator temp-file handling is predictable and not integrity-protected, which adds a local tampering/integrity risk. Overall, the code’s security risk is dominated by authorization and input-to-privileged-action issues rather than overt malicious payloads.

Confidence: 0.60

Severity: 0.62

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 72.0% likely to have a medium risk anomaly

Notes: This module is primarily a GA4 telemetry sender and does not show classic malware behaviors (no code execution, no reverse shell, no suspicious process/file actions). However, it embeds hardcoded GA4 apiSecret fallback values (for cli/emulator/vscode) and sends event payloads (including caller-provided params) to google-analytics.com. If those apiSecret values are sensitive/usable, that increases supply-chain exposure risk; also, validateOnly mode can log response bodies. Overall: likely benign telemetry with a moderate security/supply-chain concern due to embedded secrets and unvalidated telemetry parameters.

Confidence: 0.72

Severity: 0.52

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 63.0% likely to have a medium risk anomaly

Notes: This code is a Docker build/export orchestrator with multiple high-impact execution points. It runs unvalidated command strings supplied by configuration/spec and executes JavaScript generated from bundle/hook inputs inside a Docker build stage. If any of those inputs can be attacker-controlled, the module can enable arbitrary code execution in the build pipeline and can publish a compromised image to a remote registry. No overt malicious payload is visible in this snippet, but the injection/code-execution pathways make the security risk substantial and should be reviewed/locked down with strict allowlisting and input validation.

Confidence: 0.63

Severity: 0.68

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 62.0% likely to have a medium risk anomaly

Notes: No direct evidence of intentional malware (exfiltration, backdoor, credential theft) exists in this snippet. The security risk is primarily from operational behaviors: it runs npm commands via execSync (npm run build, npm pack ...) and dynamically loads the target project code (require(root)/dynamicImport(root)), which will execute arbitrary code if the target is untrusted. Additionally, it generates executable bootstrap code by embedding packageJson.name into require/import strings, creating a code-generation sink. Use only with trusted inputs and in a sandboxed environment.

Confidence: 0.62

Severity: 0.55

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 98.0% likely to have a medium risk anomaly

Notes: No evidence of malicious behavior or supply-chain malware is present. The module performs expected virtual-environment command execution and child-process cleanup. However, runWithVirtualEnv exposes a command-injection risk because untrusted commandAndArgs, cwd, or venvDir values are used with shell:true without shell escaping. Callers should restrict these inputs or avoid shell execution and invoke the executable directly.

Confidence: 0.98

Severity: 0.58

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 72.0% likely to have a medium risk anomaly

Notes: This module is not overtly malicious (no network/file-stealing logic is present in the fragment), but it is a high-risk execution relay: it launches a script/command determined by process.argv and passes through env/cwd/stdio. The non-Node path uses child_process.spawn with shell:true, which significantly increases the potential for command injection if the caller/invocation arguments are attacker-influenced. If used in a supply-chain context, strict upstream validation/allowlisting of the target script/command and removal of shell:true risk are essential; behavior also depends on unseen helper functions for path handling.

Confidence: 0.72

Severity: 0.68

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 66.0% likely to have a medium risk anomaly

Notes: No direct indicators of covert malware (e.g., exfiltration, credential theft, persistence, or obfuscated payloads) are present in this code fragment. However, it has high-impact execution behavior: it downloads an external JAR and immediately executes it via 'java -jar' without integrity verification shown here, and it supports an environment-variable override that can redirect execution to an arbitrary JAR path. The main security risk is supply-chain/code-execution via unverified artifact or environment manipulation, with secondary risk of argument-driven misuse and potential log/exception information disclosure.

Confidence: 0.66

Severity: 0.66

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 62.0% likely to have a medium risk anomaly

Notes: This code primarily functions as an emulator/dev-server launcher, but it carries meaningful supply-chain and process-execution risk. The standout concern is that it intentionally runs npm run postinstall for discovered local @firebase/util dependency instances, with an environment that can include resolved secrets. Additionally, it executes a command string via spawnWithCommandString where options.startCommand may be caller-influenced; safety depends on whether spawnWithCommandString properly tokenizes/escapes inputs. No overt malware (e.g., exfiltration, backdoors, eval-based payloads) is evident in this snippet; risk is driven by lifecycle-script execution and command execution surfaces.

Confidence: 0.62

Severity: 0.66

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block
Low priority
Potential code anomaly (AI signal): npm firebase-tools is 65.0% likely to have a medium risk anomaly

Notes: This module is a lifecycle hook runner that executes hook command strings from configuration using child_process.spawn with shell:true and minimal quote escaping. While there is no direct evidence of hidden malware in this snippet (no network/persistence/exfiltration indicators), the command execution surface is security-relevant: if an attacker can influence config[hook], they may be able to inject shell metacharacters and execute arbitrary commands. Additionally, it logs full command strings, which can leak secrets if present in commands.

Confidence: 0.65

Severity: 0.58

From: examples/firebase-functions/package-lock.json → npm/[email protected]

ℹ Read more on: This package | This alert | What is an AI-detected potential code anomaly?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at [email protected].

Suggestion: An AI system found a low-risk anomaly in this package. It may still be fine to use, but you should check that it is safe before proceeding.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/[email protected]. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Block

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants