resolve-docker-vulnerabilities

Skill to resolve Docker vulnerabilities for the firebase-cli image. Use this skill when you need to check for vulnerabilities in the firebase-cli Docker image…

npx skills add https://github.com/firebase/firebase-tools --skill resolve-docker-vulnerabilities

Resolve Docker Vulnerabilities

This skill guides you through the process of listing images, checking for vulnerabilities, planning remediation, and verifying the fixes by publishing to a staging repository.

Workflow

1. Publish to Staging

Run the build on fir-tools-builds and publish to the staging repository in firebase-cli to see the baseline vulnerabilities after the build's own updates.

./scripts/publish/firebase-docker-image/run.sh --build-project fir-tools-builds --repo staging --target firebase-cli

2. Check Vulnerabilities

Check the vulnerability reports for the image just pushed to staging. You will need to find the digest of the image first.

gcloud artifacts docker images list us-docker.pkg.dev/firebase-cli/staging/firebase

Then check vulnerabilities using the digest:

gcloud artifacts vulnerabilities list us-docker.pkg.dev/firebase-cli/staging/firebase@sha256:<DIGEST>

To investigate which layers and file paths are causing the vulnerabilities, run the command with --format=json:

gcloud artifacts vulnerabilities list us-docker.pkg.dev/firebase-cli/staging/firebase@sha256:<DIGEST> --format=json

Look for fileLocation and layerDetails in the output to understand if the vulnerability is in:

  • Project dependencies (e.g., under /usr/local/node_packages/node_modules). Recommend updating the package.json and running the build again. You can use overrides as needed here to upgrade transitive dependencies to non-breaking versions.
  • Global tools (e.g., under /usr/local/lib/node_modules/npm). Recommend waiting for upstream fixes (which will be pulled in as soon as they are available).
  • External binaries (e.g., emulator JARs under /root/.cache/firebase/emulators). Recommend raising these issues to the team owning the emulator.

3. Plan Remediation

For each vulnerable package identified:

  • Determine if it can be updated in the Dockerfile.
  • Check if a fix is available.
  • Create a plan to address it (e.g., upgrading the base image, upgrading the specific package).

4. Present Plan to User

Present the proposed plan to the user for approval before making changes.

5. Apply Fix and Re-Verify

After making changes to the Dockerfile or related files, repeat Step 1 and Step 2 to publish a new staged image and verify that the vulnerabilities have been resolved.

Mehr Skills von firebase

developing-genkit-dart
firebase
Einheitliches AI SDK für Dart, das Codegenerierung, strukturierte Ausgaben, Tools, Flows und Agents ermöglicht. Bietet Kern-APIs für Generierung, Tool-Definition, Flow-Orchestrierung, Embeddings und Streaming mit einer einzigen Schnittstelle. Enthält 8+ Plugins für LLM-Anbieter (Google Gemini, Anthropic Claude, OpenAI GPT), Firebase AI, Model Context Protocol, Chrome-Browser-Integration und HTTP-Server-Hosting über Shelf. Integrierte CLI mit lokaler Entwicklungs-UI für Flow-Ausführung, Tracing, Modellexperimentierung und...
official
developing-genkit-js
firebase
Erstellen Sie KI-gestützte Node.js/TypeScript-Anwendungen mit Genkit-Flows, Tools und Multi-Modell-Unterstützung. Genkit ist anbieterneutral; unterstützt Google AI, OpenAI, Anthropic, Ollama und andere LLM-Anbieter über Plugins. Definieren Sie Flows mit typsicheren Schemas mit Zod, führen Sie Generierungsanfragen aus und erstellen Sie mehrstufige KI-Workflows in TypeScript. Erfordert Genkit CLI v1.29.0+; aufgrund aktueller größerer API-Änderungen müssen Sie die Genkit-Dokumentation:read und common-errors.md für aktuelle Muster konsultieren, nicht auf früherem Wissen basieren...
official
extension-to-functions-codebase
firebase
Skill for converting an installed Firebase Extension (or extension source) into a standalone Cloud Functions for Firebase codebase or publishable npm package,…
official
firebase-ai-logic
firebase
We need to translate the given English text into German, preserving the name "firebase-ai-logic" but it's not in the text. The instruction says: "Do not include the name unless it appears in the source text." The name does not appear in the source text, so we don't include it. We just translate the text inside <text>. Also preserve product names, protocol names, URLs, numbers, technical terms. So "Gemini", "Gemini Nano", "Chrome", "Cloud Storage", "App Check" should remain as is. Translate the rest naturally. Let me translate: "Client-side Gemini integration for web apps with multimodal inference, streaming, and on-device hybrid execution." -> "Clientseitige Gemini-Integration für Web-Apps mit multimodaler Inferenz, Streaming und hybrider Ausführung auf dem Gerät." "Supports text-only and multimodal inputs (images, audio, video, PDFs); files over 20 MB route through Cloud Storage" -> "Unterstützt reine Texteingaben und multim
official
firebase-ai-logic-basics
firebase
Offizielle Fähigkeit zur Integration von Firebase AI Logic (Gemini API) in Webanwendungen. Behandelt Einrichtung, multimodale Inferenz, strukturierte Ausgabe und Sicherheit.
official
firebase-app-hosting-basics
firebase
Bereitstellen und Verwalten von Full-Stack-Web-Apps mit Firebase App Hosting unter Verwendung von Next.js, Angular und anderen unterstützten Frameworks. Erfordert ein Firebase-Projekt im Blaze-Tarif; unterstützt Server-Side Rendering (SSR) und Incremental Static Regeneration (ISR)-Workflows. Bereitstellung über firebase.json-Konfiguration mit optionaler apphosting.yaml für das Backend-Setup oder aktiviertes automatisiertes "git push to deploy" durch GitHub-Integration. Enthält Geheimnisverwaltung über CLI-Befehle für sicheren Zugriff auf sensible Schlüssel...
official
firebase-auth-basics
firebase
Richten Sie Firebase Authentication mit mehreren Identitätsanbietern und sicheren Datenzugriffsregeln ein. Unterstützt E-Mail/Passwort, Telefonnummer, anonyme, föderierte Anbieter (Google, Facebook, Twitter, GitHub, Microsoft, Apple) und benutzerdefinierte Authentifizierungsintegration. Jeder authentifizierte Benutzer erhält eine eindeutige ID und JWT-basierte Token (kurzlebige ID-Token und langlebige Refresh-Token) für den Zugriff auf Firebase-Dienste. Aktivieren Sie Anbieter über die CLI für Google Sign In, anonyme Anmeldung und E-Mail/Passwort; nutzen Sie die Firebase-Konsole...
official
firebase-basics
firebase
Firebase-Projekt-Setup und CLI-Workflow für die Integration von KI-Agenten. Erfordert die vorherige Durchführung der firebase-local-env-setup-Fähigkeit und die Installation der Firebase-CLI. Der Kern-Workflow umfasst die Authentifizierung über firebase login, die Projekterstellung mit eindeutigen IDs und die Dienstinitialisierung über den interaktiven Befehl firebase init. Unterstützt die Funktionsauswahl während des Setups, einschließlich Firestore, Functions und Hosting, mit automatischer Generierung von Konfigurationsdateien. Selbst dokumentierende CLI mit --help-Flags für...
official