Skip to content

chore(deps): update firebase/agent-skills digest to e35a2d5 - #919

Open
renovate[bot] wants to merge 4 commits into
mainfrom
renovate/firebase-agent-skills-digest
Open

renovate[bot] wants to merge 4 commits into
mainfrom
renovate/firebase-agent-skills-digest

Conversation

@renovate

@renovate renovate Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
firebase/agent-skills digest 073edf7e35a2d5

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@toolhive-release-app

toolhive-release-app Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

🛡️ Skill Security Scan Results

✅ firebase-ai-logic-basics

  • Status: Passed
  • Findings: 3

✅ firebase-app-hosting-basics

  • Status: Passed
  • Findings: 2

✅ firebase-auth-basics

  • Status: Passed
  • Findings: 1

✅ firebase-hosting-basics

  • Status: Passed
  • Findings: 1

✅ firebase-security-rules-auditor

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: firebase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

Summary: Completed 5 of 5 skill scan(s), all passed security checks. ✅

@renovate renovate Bot changed the title chore(deps): update firebase/agent-skills digest to a0b4e14 chore(deps): update firebase/agent-skills digest to e35a2d5 Sep 18, 2026
@renovate
renovate Bot force-pushed the renovate/firebase-agent-skills-digest branch from ea538ee to d903992 Compare September 18, 2026 14:42
…e-app-hosting-basics,firebase-auth-basics,firebase-basics,firebase-data-connect-basics,firebase-firestore,firebase-hosting-basics,firebase-security-rules-auditor
@renovate

renovate Bot commented Sep 18, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@danbarr

danbarr commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Security triage complete.

Allowed findings: none. The official Firebase publisher and pinned source do not mitigate the following real risks:

  • firebase-basicsLLM_COMMAND_INJECTION: user-controlled values are interpolated into shell templates, including a double-quoted display name; LLM_SUPPLY_CHAIN_ATTACK: npx -y firebase-tools@latest and remote skill/plugin updates execute mutable upstream artifacts.
  • firebase-data-connect-basicsLLM_SUPPLY_CHAIN_ATTACK: mutable npx -y firebase-tools@latest is executed for initialization, generation, validation, and deployment; LLM_HARMFUL_CONTENT: the CRUD update/delete example authorizes any USER without a per-record ownership check.
  • firebase-firestoreLLM_COMMAND_INJECTION: database IDs/locations are interpolated into shell commands without an argument-safe boundary.

No exclusion was added; these must remain blocking. Validated pinned sources with task validate-skill -- skills/firebase-basics, skills/firebase-data-connect-basics, and skills/firebase-firestore.

Signed-off-by: Dan Barr <danbarr@users.noreply.github.com>
@danbarr

danbarr commented Sep 18, 2026

Copy link
Copy Markdown
Contributor

Correction: deferred the firebase-basics, firebase-data-connect-basics, and firebase-firestore updates to their PR-base ref/version values. Final status depends on the authoritative GitHub Trusted Skill Scan.

@danbarr
danbarr enabled auto-merge (squash) September 18, 2026 17:47
@danbarr
danbarr disabled auto-merge September 18, 2026 19:03
Signed-off-by: Dan Barr <6922515+danbarr@users.noreply.github.com>
@danbarr
danbarr enabled auto-merge (squash) September 18, 2026 19:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant