Skip to content

chore(deps): bump stream-json and firebase-tools - #819

Merged
tyler-reitz merged 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-84b0a93e8e
Oct 10, 2026
Merged

tyler-reitz merged 1 commit into
mainfrom
dependabot/npm_and_yarn/multi-84b0a93e8e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor

Bumps stream-json to 3.7.0 and updates ancestor dependency firebase-tools. These dependencies need to be updated together.

Updates stream-json from 1.8.0 to 3.7.0

Commits
  • ac4a46d New version: 3.7.0.
  • ca2bb67 Removed dead code.
  • c06c9a3 Perf optimization.
  • 1929fd8 Added depth capping for DoS hardening.
  • 9e35c67 Bump the npm-deps group with 2 updates (#222)
  • 945c62f Bump @​types/node from 26.4.0 to 26.5.0 in the npm-deps group (#221)
  • 77a4946 New version: 3.6.0.
  • 0291333 Added simplified replacement + fast check tests.
  • 0c816ae Bump @​types/node from 26.2.0 to 26.3.0 in the npm-deps group (#219)
  • c0299dc Reworked how comments are handled in JSONC.
  • Additional commits viewable in compare view

Updates firebase-tools from 15.22.3 to 15.33.0

Release notes

Sourced from firebase-tools's releases.

v15.33.0

  • Updated Firebase Hosting API requests to be project-scoped, eliminating site-scoped requests and the use of - as a project identifier.
  • Added check for a default Hosting site and offer to create one during firebase apps:create web.
  • Added a check for a default Hosting site and offer to create one during auth initialization.
  • Started reporting the GCFv2-to-GCFv1 downgrade error during validation instead of a misleading CPU error (#5461).
  • Fixed functions:delete recreating an already-deleted Cloud Tasks queue for task queue functions. (#9305)
  • Batched function deletions across instances when uninstalling a Function Kit (#11189).
  • Fixed an issue where 2nd-gen functions with parameterized trigger event filters failed default region resolution (#11020).
  • Fixed functions:lifecycle:list and functions:lifecycle:run failing to detect Function Kit instances (#11240).
  • Fixed nested ternary CEL expressions in function parameters, which previously failed to load or selected the wrong branch. (#7755)

v15.32.1

  • Improved error message when billing is not enabled
  • Fixed a crash in setEnqueuer when deploying Cloud Tasks functions whose IAM policy has no bindings (#11184).
  • Updated dependencies to address security vulnerabilities, including protobufjs, tar, @grpc/grpc-js, express, undici, hono, tmp, and form-data.
  • Updated the Firebase SQL Connect local toolkit to v3.4.22, which includes the following changes:
    • [fixed] Disallow using the GraphQL root operation type names (Query, Mutation, Subscription) as @table or @view types.
  • Added an optional step to configure Crashlytics email alerts during crashlytics:onboard:web.
  • Fixed 404 errors during crashlytics:sourcemap:upload when re-uploading a source map with the same obfuscated file path across different app versions

v15.32.0

  • Increased retries for IAM policy updates to further reduce deployment flakiness from service account propagation delays.
  • Preselect the default values of list function params in multi-select prompts.
  • Fixed ERR_REQUIRE_ESM crash (e.g. on emulators:start) in the standalone binary and on Node.js versions earlier than 20.19 / 22.12. (#11168)
  • Updated the Firebase console link in the Terms of Service error to include ?forceCheckTos=true.
  • Honor boolean and integer defaults in select prompts for function params instead of preselecting the first option.
  • Added support for overriding the Cloud Secret Manager secret ID and version used to resolve a named secret parameter via FIREBASE_SECRET_REF_<SECRET_NAME> in Functions .env files.
  • Introduced function kits (functions:kits:install, functions:kits:uninstall, functions:kits:list) to configure and run multiple instances of functions from the CLI.
  • Added ext:migrate and updated ext:export and ext:list to assist with migrating Firebase Extensions to function kits.

v15.31.0

  • Improved error message with a link to the Firebase console when projects:addfirebase fails due to unaccepted Firebase Terms of Service.
  • Fixed firebase deploy leaving the Python discovery admin server (serving.py) running after a killed or wedged deploy, which caused later deploys to hang indefinitely on connect ETIMEDOUT (#10847).
  • SQL Connect generated Admin Node SDKs now support firebase-admin v14.
  • Allow pre-existing Crashlytics source maps to be overwritten instead of returning an error.
  • Fixed Crashlytics source map uploads for Angular builds to strip out leading directory paths (e.g., /dist/angular/browser/).

v15.30.2

  • Improved formatting and user experience for Cloud Functions parameter and secret prompts.
  • Updated the Firebase SQL Connect local toolkit to v3.4.20.
  • Fixed an issue where 2nd Gen Firebase Authentication triggers (onUserCreated and onUserDeleted) did not work in the local Functions and Auth Emulators.

v15.30.1

  • [fixed] Fail fast with an actionable error and remediation instructions when declarative security APIs (IAM and Cloud Resource Manager) are disabled on the project.
  • Updated Pub/Sub emulator to version 0.8.36.
  • [fixed] Clean up managed service accounts when opting out of declarative security alongside a filtered codebase deploy.
  • ext:uninstall --immediate now warns about secrets bound to the extension that will be deleted and offers a migration path.
  • [fixed] Generate deterministic unsalted ETags for declarative security roles.

v15.30.0

... (truncated)

Commits
  • 40cff80 15.33.0
  • 7372696 Add direct_cloud_run experiment flag (#11203)
  • a91d282 Update Shared Cloud Run v2 API to Support Cloud Run Deploys (#11202)
  • 2343e36 docs: align GEMINI.md with PR review standards and conventions (#11243)
  • dc2e5cc fix(functions): resolve nested ternary CEL expressions in params (#11093)
  • 0c54cf8 refactor(hosting): use project-scoped endpoints for all Hosting API requests ...
  • 8c344bf adding cloud trace storage provisioning to crashlytics onboarding (#11219)
  • 2b61f7e [AI Improvement] [Task] Block real outbound network in unit tests with nock.d...
  • 30f9576 fix(functions): read function kit instances in functions:lifecycle commands (...
  • 459aef1 fix(functions): resolve default regions for parameterized event triggers (#11...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [stream-json](https://github.com/uhop/stream-json) to 3.7.0 and updates ancestor dependency [firebase-tools](https://github.com/firebase/firebase-tools). These dependencies need to be updated together.


Updates `stream-json` from 1.8.0 to 3.7.0
- [Commits](uhop/stream-json@1.8.0...3.7.0)

Updates `firebase-tools` from 15.22.3 to 15.33.0
- [Release notes](https://github.com/firebase/firebase-tools/releases)
- [Changelog](https://github.com/firebase/firebase-tools/blob/main/CHANGELOG.md)
- [Commits](firebase/firebase-tools@v15.22.3...v15.33.0)

---
updated-dependencies:
- dependency-name: stream-json
  dependency-version: 3.7.0
  dependency-type: indirect
- dependency-name: firebase-tools
  dependency-version: 15.33.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code labels Oct 10, 2026
@tyler-reitz
tyler-reitz merged commit 99a88ee into main Oct 10, 2026
15 checks passed
@tyler-reitz
tyler-reitz deleted the dependabot/npm_and_yarn/multi-84b0a93e8e branch October 10, 2026 00:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant