@firebase/storage-compat
The Firebase Firestore compatibility package
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@firebase/util | AI (dependencies): First-party Google Firebase package from the same official monorepo; unvetted status is a pipeline artifact, not a security concern for this package. | ai | |
| dependencies | unvetted-dep:@firebase/storage | AI (dependencies): First-party Google Firebase package from the same official monorepo; unvetted status is a pipeline artifact, not a security concern for this package. | ai | |
| dependencies | unvetted-dep:@firebase/storage-types | AI (dependencies): First-party Google Firebase package from the same official monorepo; unvetted status is a pipeline artifact, not a security concern for this package. | ai | |
| provenance | publisher-changed | AI (provenance): feiyang.chen is an established Firebase/Google publisher (2779 days, 1044 approved packages). Publisher changes within the Firebase SDK team are expected for this monorepo package. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a standard TypeScript runtime helper declared in dependencies; phantom detection is a false positive for compiled TS packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Missing README/repo/keywords are typical for @firebase/* scoped sub-packages in a monorepo; not indicative of spam or malicious intent. | ai |
Versions (showing 86 of 286)
v0.3.23-canary.5d13166dc
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23-canary.47b154c75
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23-canary.42ac40117
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23-canary.41e3c4cdf
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23-canary.3d44792f1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23-canary.247b92f9b
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23-canary.13e6cce88
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.23-20250610123508
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.ec91a8611
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.d5e5795c9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.d590889d6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.c0617a341
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.af9f8b552
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.9964849e9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.8cb21ffc5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.89051ca4d
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.770e455a6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.6cc9a0732
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.5871fd656
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.40be2dbb8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.30de503ec
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.230692087
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.1933324e0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-canary.0f891d861
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-20250521232236
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.22-20250520183425
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.21-canary.b5df4ae71
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.21-canary.35ad52663
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.21-canary.2fe754727
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.21-20250515171652
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.20-canary.880110bba
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.20-canary.3d9291f47
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.20-20250514221114
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.19-20250513212531
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.19-20250513210731
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.19-20250512211235
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-eap-ai-hybridinference.c16cbf1a3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-eap-ai-hybridinference.58d92df33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.f92069a21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.f8334eade
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.e99683b17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.d5428f3d2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.d5082f9f2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.8a03143b9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.88584fdeb
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.799de5997
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.72852e12d
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.6be75f74d
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.51e7b489d
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.39505cc72
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-canary.050c1b6a0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-20250507151459
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-20250507150015
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.18-20250505162014
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-ssl-check.4f23f3343
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-eap-vertexai-hybgoog.dc3794a2b
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-eap-vertexai-hybgoog.abf0491ae
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-eap-vertexai-hybgoog.31261ca31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.ea1f9139e
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.dd6a8f076
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.9952dbc2d
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.6a02778e3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.3789b5ad1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.20b45d3ab
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.0e2558a96
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.0e1276649
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.17-canary.080a90dcc
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.