Skip to content

[AI Improvement] [Task] Upgrade firebase-admin devDependency from ^11 to the latest major - #11197

Draft
joehan wants to merge 3 commits into
mainfrom
ai-improve-567662510-task-upgrade-firebase-admin-devdepe
Draft

joehan wants to merge 3 commits into
mainfrom
ai-improve-567662510-task-upgrade-firebase-admin-devdepe

Conversation

@joehan

@joehan joehan commented Sep 29, 2026

Copy link
Copy Markdown
Member

Resolves Buganizer b/567662510 (parent goal: b/567660818)

Proposed Improvement

  • Upgrades root firebase-admin devDependency from ^11.5.0 to ^14.5.0.
  • Resolves high/critical dev vulnerabilities flagged by npm audit from @google-cloud/firestore 6.x → google-gax 4.x → protobufjs-cli (4 advisories) and older nested protobufjs.
  • Removes obsolete overrides.firebase-admin (pinning uuid: ^11.1.1), as firebase-admin@14 no longer bundles uuid or @google-cloud/firestore directly.
  • Adds package override "firebase-functions": { "firebase-admin": "-admin" } to satisfy firebase-functions@4.3.1 peerDependency requirement without breaking resolution.
  • Updates emulator test and integration scripts to use the modular Admin SDK subpaths (firebase-admin/app, firebase-admin/storage, firebase-admin/database, firebase-admin/auth, firebase-admin/firestore).
  • Rebuilt and normalized npm-shrinkwrap.json under Node 24 using npx -y npm@11.9 install --package-lock-only --ignore-scripts with zero drift.

Verification

  • npm run build: Passed cleanly (built MCP apps and compiled TypeScript).
  • npm run test:compile: Passed cleanly (0 TypeScript errors across the repository).
  • npm run lint:quiet: Passed cleanly across the entire repository (0 errors).
  • npm run generate:json-schema && git diff --exit-code -- schema/: Verified schema consistency.
  • Mocha unit tests: adminSdkConfig, functionsEmulatorShared, functionsEmulatorUtils, and functionsRuntimeWorker passed cleanly (51 passing).
  • npm audit: Completely cleared firebase-admin, @google-cloud/firestore, google-gax, and protobufjs-cli vulnerabilities.

@joehan joehan self-assigned this Sep 29, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request upgrades the firebase-admin dependency to ^14.5.0 and refactors various integration and conformance test files to adopt the modular Firebase Admin SDK APIs. The review feedback identifies a common issue across several conformance tests where calling deleteApp(getApp()) in the after hook can throw a FirebaseAppError if the before hook fails prior to initialization, which masks the actual setup error. To resolve this, the reviewer suggests importing getApps and safely cleaning up any initialized apps using getApps().map(app => deleteApp(app)).

import { Bucket } from "@google-cloud/storage";
import { expect } from "chai";
import * as admin from "firebase-admin";
import { applicationDefault, cert, deleteApp, getApp, initializeApp } from "firebase-admin/app";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Import getApps instead of getApp to safely clean up all initialized apps in the after hook without throwing an error if the default app was never initialized (e.g., if the before hook failed).

import { applicationDefault, cert, deleteApp, getApps, initializeApp } from "firebase-admin/app";

});

after(async function (this) {
this.timeout(EMULATORS_SHUTDOWN_DELAY_MS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using deleteApp(getApp()) in the after hook will throw a FirebaseAppError if the before hook failed before initializeApp was called. This masks the actual setup error with a confusing "The default Firebase app does not exist" error. Use getApps() to safely delete any initialized apps instead.

    await Promise.all(getApps().map((app) => deleteApp(app)));

import { Bucket, CopyOptions } from "@google-cloud/storage";
import { expect } from "chai";
import * as admin from "firebase-admin";
import { applicationDefault, cert, deleteApp, getApp, initializeApp } from "firebase-admin/app";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Import getApps instead of getApp to safely clean up all initialized apps in the after hook without throwing an error if the default app was never initialized.

import { applicationDefault, cert, deleteApp, getApps, initializeApp } from "firebase-admin/app";

@@ -65,7 +66,7 @@ describe("GCS Javascript SDK conformance tests", () => {

after(async function (this) {
this.timeout(EMULATORS_SHUTDOWN_DELAY_MS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using deleteApp(getApp()) in the after hook will throw a FirebaseAppError if the before hook failed before initializeApp was called. This masks the actual setup error with a confusing "The default Firebase app does not exist" error. Use getApps() to safely delete any initialized apps instead.

    await Promise.all(getApps().map((app) => deleteApp(app)));

import { Bucket } from "@google-cloud/storage";
import { expect } from "chai";
import * as admin from "firebase-admin";
import { applicationDefault, cert, deleteApp, getApp, initializeApp } from "firebase-admin/app";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Import getApps instead of getApp to safely clean up all initialized apps in the after hook without throwing an error if the default app was never initialized.

import { applicationDefault, cert, deleteApp, getApps, initializeApp } from "firebase-admin/app";

@@ -75,7 +76,7 @@ describe("GCS endpoint conformance tests", () => {

after(async function (this) {
this.timeout(EMULATORS_SHUTDOWN_DELAY_MS);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using deleteApp(getApp()) in the after hook will throw a FirebaseAppError if the before hook failed before initializeApp was called. This masks the actual setup error with a confusing "The default Firebase app does not exist" error. Use getApps() to safely delete any initialized apps instead.

    await Promise.all(getApps().map((app) => deleteApp(app)));

import * as puppeteer from "puppeteer";
import { expect } from "chai";
import * as admin from "firebase-admin";
import { applicationDefault, cert, deleteApp, getApp, initializeApp } from "firebase-admin/app";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Import getApps instead of getApp to safely clean up all initialized apps in the after hook without throwing an error if the default app was never initialized.

import { applicationDefault, cert, deleteApp, getApps, initializeApp } from "firebase-admin/app";

after(async function (this) {
this.timeout(EMULATORS_SHUTDOWN_DELAY_MS);
admin.app().delete();
await deleteApp(getApp());

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using deleteApp(getApp()) in the after hook will throw a FirebaseAppError if the before hook failed before initializeApp was called. This masks the actual setup error with a confusing "The default Firebase app does not exist" error. Use getApps() to safely delete any initialized apps instead.

    await Promise.all(getApps().map((app) => deleteApp(app)));

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants