@firebase/performance
Firebase performance for web
100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
firebase-opsfeiyang.chengoogle-wombotchholland
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Firebase SDK packages consistently lack Sigstore provenance; this is a known gap in their publishing pipeline, not a per-version risk signal. | ai | |
| provenance | publisher-changed | AI (provenance): google-wombot is Google's official Firebase SDK automation publisher; publisher transitions to this account are expected and legitimate for @firebase/* packages. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Firebase SDK maintainer roster changes over time are expected for a long-lived Google project; removal of individual maintainers is not a takeover signal here. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy signal is an artifact of comparing against a very old approved version (v0.2.6); the package has 3087 versions in registry indicating continuous active development. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): web-vitals is Google's own Core Web Vitals library; @firebase/component is part of the Firebase SDK. Both are legitimate, well-established dependencies for a performance monitoring package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): This is a legitimate Firebase SDK sub-package from Google's monorepo. Short README and missing keywords are typical for internal SDK packages, not spam indicators. | ai | |
| dependencies | unvetted-dep:@firebase/util | AI (dependencies): First-party Firebase SDK dependency from the same Google monorepo; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@firebase/logger | AI (dependencies): First-party Firebase SDK dependency from the same Google monorepo; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@firebase/installations | AI (dependencies): First-party Firebase SDK dependency from the same Google monorepo; not a third-party risk. | ai | |
| dependencies | unvetted-dep:@firebase/performance-types | AI (dependencies): First-party Firebase SDK dependency from the same Google monorepo; not a third-party risk. | ai |
Versions (showing 100 of 113)
| Version | Deps | Published |
|---|---|---|
| 0.7.12 | 6 / 5 | |
| 0.7.11 | 6 / 5 | |
| 0.7.10 | 6 / 5 | |
| 0.7.9 | 6 / 5 | |
| 0.7.8 | 6 / 5 | |
| 0.7.7 | 6 / 5 | |
| 0.7.6 | 6 / 5 | |
| 0.7.5 | 6 / 5 | |
| 0.7.4 | 6 / 5 | |
| 0.7.3 | 6 / 5 | |
| 0.7.2 | 6 / 5 | |
| 0.7.1 | 6 / 5 | |
| 0.7.0 | 6 / 5 | |
| 0.6.12 | 5 / 5 | |
| 0.6.11 | 5 / 5 | |
| 0.6.10 | 5 / 5 | |
| 0.6.9 | 5 / 5 | |
| 0.6.8 | 5 / 5 | |
| 0.6.7 | 5 / 5 | |
| 0.6.6 | 5 / 5 | |
| 0.6.5 | 5 / 5 | |
| 0.6.4 | 5 / 5 | |
| 0.6.3 | 5 / 5 | |
| 0.6.2 | 5 / 5 | |
| 0.6.1 | 5 / 5 | |
| 0.6.0 | 5 / 5 | |
| 0.5.17 | 5 / 5 | |
| 0.5.16 | 5 / 5 | |
| 0.5.15 | 5 / 5 | |
| 0.5.14 | 5 / 5 | |
| 0.5.13 | 5 / 5 | |
| 0.5.12 | 5 / 5 | |
| 0.5.11 | 5 / 5 | |
| 0.5.10 | 5 / 5 | |
| 0.5.9 | 5 / 5 | |
| 0.5.8 | 5 / 5 | |
| 0.5.7 | 5 / 5 | |
| 0.5.6 | 5 / 5 | |
| 0.5.5 | 5 / 5 | |
| 0.5.4 | 5 / 5 | |
| 0.5.3 | 5 / 5 | |
| 0.5.2 | 5 / 5 | |
| 0.5.1 | 5 / 5 | |
| 0.5.0 | 5 / 5 | |
| 0.4.18 | 6 / 5 | |
| 0.4.17 | 6 / 5 | |
| 0.4.16 | 6 / 5 | |
| 0.4.15 | 6 / 5 | |
| 0.4.14 | 6 / 5 | |
| 0.4.13 | 6 / 5 | |
| 0.4.12 | 6 / 5 | |
| 0.4.11 | 6 / 5 | |
| 0.4.10 | 6 / 5 | |
| 0.4.9 | 6 / 5 | |
| 0.4.8 | 6 / 5 | |
| 0.4.7 | 6 / 5 | |
| 0.4.6 | 6 / 5 | |
| 0.4.5 | 6 / 5 | |
| 0.4.4 | 6 / 5 | |
| 0.4.3 | 6 / 5 | |
| 0.4.2 | 6 / 5 | |
| 0.4.1 | 6 / 5 | |
| 0.4.0 | 6 / 4 | |
| 0.3.11 | 6 / 4 | |
| 0.3.10 | 6 / 4 | |
| 0.3.9 | 6 / 4 | |
| 0.3.8 | 6 / 4 | |
| 0.3.7 | 6 / 4 | |
| 0.3.6 | 6 / 4 | |
| 0.3.5 | 6 / 4 | |
| 0.3.4 | 6 / 4 | |
| 0.3.3 | 6 / 4 | |
| 0.3.2 | 6 / 4 | |
| 0.3.1 | 6 / 4 | |
| 0.3.0 | 6 / 4 | |
| 0.2.37 | 6 / 4 | |
| 0.2.36 | 6 / 4 | |
| 0.2.35 | 6 / 4 | |
| 0.2.34 | 6 / 4 | |
| 0.2.33 | 6 / 4 | |
| 0.2.32 | 6 / 4 | |
| 0.2.31 | 6 / 4 | |
| 0.2.30 | 6 / 4 | |
| 0.2.29 | 6 / 4 | |
| 0.2.28 | 6 / 4 | |
| 0.2.27 | 6 / 4 | |
| 0.2.26 | 5 / 19 | |
| 0.2.25 | 5 / 19 | |
| 0.2.24 | 5 / 19 | |
| 0.2.23 | 5 / 19 | |
| 0.2.22 | 5 / 19 | |
| 0.2.21 | 5 / 19 | |
| 0.2.20 | 5 / 19 | |
| 0.2.19 | 5 / 19 | |
| 0.2.18 | 5 / 19 | |
| 0.2.17 | 5 / 19 | |
| 0.2.16 | 5 / 19 | |
| 0.2.15 | 5 / 19 | |
| 0.2.14 | 5 / 19 | |
| 0.2.13 | 5 / 19 |
Showing 100 of 113
Next page →
v0.7.12
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.