@firebase/functions-compat
51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
firebase-opsfeiyang.chengoogle-wombotchholland
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@firebase/util | AI (dependencies): @firebase/util is a sibling Firebase SDK package from the same Google/Firebase publisher; unvetted status is a pipeline artifact, not a real risk for this package. | ai | |
| dependencies | unvetted-dep:@firebase/functions | AI (dependencies): @firebase/functions is the core sibling package this compat wrapper depends on; same publisher/monorepo, not a real risk. | ai | |
| provenance | publisher-changed | AI (provenance): chholland is a long-standing Firebase/Google publisher (2677 days, 1138 approved packages). Publisher rotation within the Firebase team is expected and not indicative of compromise. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Firebase monorepo sub-packages commonly omit descriptions; this is a known pattern for @firebase/* compat packages, not a malware indicator. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper dependency used by all Firebase SDK packages; its implicit usage is expected and benign. | ai | |
| provenance | no-provenance | AI (provenance): Google/Firebase publishes via google-wombot without Sigstore provenance; this is consistent across all @firebase/* packages and not a risk signal. | ai |
Versions (showing 51 of 287)
| Version | Deps | Published |
|---|---|---|
| 0.4.5 | 5 / 5 | |
| 0.4.4 | 5 / 5 | |
| 0.4.3 | 5 / 5 | |
| 0.4.2 | 5 / 5 | |
| 0.4.1 | 5 / 5 | |
| 0.4.0 | 5 / 5 | |
| 0.3.26 | 5 / 5 | |
| 0.3.25 | 5 / 5 | |
| 0.3.24 | 5 / 5 | |
| 0.3.23 | 5 / 5 | |
| 0.3.22 | 5 / 5 | |
| 0.3.21 | 5 / 5 | |
| 0.3.20 | 5 / 5 | |
| 0.3.19 | 5 / 5 | |
| 0.3.18 | 5 / 5 | |
| 0.3.17 | 5 / 5 | |
| 0.3.16 | 5 / 5 | |
| 0.3.15 | 5 / 5 | |
| 0.3.14 | 5 / 5 | |
| 0.3.13 | 5 / 5 | |
| 0.3.12 | 5 / 5 | |
| 0.3.11 | 5 / 5 | |
| 0.3.10 | 5 / 5 | |
| 0.3.9 | 5 / 5 | |
| 0.3.8 | 5 / 5 | |
| 0.3.7 | 5 / 5 | |
| 0.3.6 | 5 / 5 | |
| 0.3.5 | 5 / 5 | |
| 0.3.4 | 5 / 5 | |
| 0.3.3 | 5 / 5 | |
| 0.3.2 | 5 / 5 | |
| 0.3.1 | 5 / 5 | |
| 0.3.0 | 5 / 5 | |
| 0.2.8 | 5 / 5 | |
| 0.2.7 | 5 / 5 | |
| 0.2.6 | 5 / 5 | |
| 0.2.5 | 5 / 5 | |
| 0.2.4 | 5 / 5 | |
| 0.2.3 | 5 / 5 | |
| 0.2.2 | 5 / 5 | |
| 0.2.1 | 5 / 5 | |
| 0.2.0 | 5 / 5 | |
| 0.1.12 | 5 / 5 | |
| 0.1.11 | 5 / 5 | |
| 0.1.10 | 5 / 5 | |
| 0.1.9 | 5 / 5 | |
| 0.1.8 | 5 / 5 | |
| 0.1.7 | 5 / 5 | |
| 0.1.6 | 5 / 5 | |
| 0.1.5 | 5 / 5 | |
| 0.1.4 | 5 / 5 |
v0.4.5
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.4
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.