@firebase/database-types
@firebase/database Types
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Firebase packages published via google-wombot consistently lack Sigstore provenance; this is a known pattern for this publisher and not a security concern. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change from jshcrowthe to chholland reflects a legitimate Firebase/Google team transition in 2019; chholland is an established Firebase publisher with 2472 approved packages. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers (chholland, feiyang.chen, google-wombot, hiranya911) are known Firebase/Google team members and automation accounts; consistent with legitimate org-level maintainer rotation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of jshcrowthe and vikrum is consistent with the same 2019 Firebase team transition; no signs of malicious takeover. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Types-only package from Firebase; sparse README and no keywords are expected for an internal types package in a large SDK monorepo. | ai |
Versions (showing 100 of 318)
v1.0.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.19-20260409172004
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.19-20260408221811
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.19-20260408201731
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18-canary.f4e0086e3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18-canary.bfb9accdc
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18-canary.ba0bc39bb
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18-canary.742e17a8e
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18-canary.44ad4cc2e
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.18-20260317152345
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.17-canary.d7b182645
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.17-canary.891a0c9d4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.17-canary.843a8d789
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.17-canary.792c61671
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.17-canary.78384d32c
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.