resolve-docker-vulnerabilities

Habilidade para resolver vulnerabilidades do Docker na imagem firebase-cli. Use esta habilidade quando precisar verificar vulnerabilidades na imagem Docker do firebase-cli…

npx skills add https://github.com/firebase/firebase-tools --skill resolve-docker-vulnerabilities

Resolve Docker Vulnerabilities

This skill guides you through the process of listing images, checking for vulnerabilities, planning remediation, and verifying the fixes by publishing to a staging repository.

Workflow

1. Publish to Staging

Run the build on fir-tools-builds and publish to the staging repository in firebase-cli to see the baseline vulnerabilities after the build's own updates.

./scripts/publish/firebase-docker-image/run.sh --build-project fir-tools-builds --repo staging --target firebase-cli

2. Check Vulnerabilities

Check the vulnerability reports for the image just pushed to staging. You will need to find the digest of the image first.

gcloud artifacts docker images list us-docker.pkg.dev/firebase-cli/staging/firebase

Then check vulnerabilities using the digest:

gcloud artifacts vulnerabilities list us-docker.pkg.dev/firebase-cli/staging/firebase@sha256:<DIGEST>

To investigate which layers and file paths are causing the vulnerabilities, run the command with --format=json:

gcloud artifacts vulnerabilities list us-docker.pkg.dev/firebase-cli/staging/firebase@sha256:<DIGEST> --format=json

Look for fileLocation and layerDetails in the output to understand if the vulnerability is in:

  • Project dependencies (e.g., under /usr/local/node_packages/node_modules). Recommend updating the package.json and running the build again. You can use overrides as needed here to upgrade transitive dependencies to non-breaking versions.
  • Global tools (e.g., under /usr/local/lib/node_modules/npm). Recommend waiting for upstream fixes (which will be pulled in as soon as they are available).
  • External binaries (e.g., emulator JARs under /root/.cache/firebase/emulators). Recommend raising these issues to the team owning the emulator.

3. Plan Remediation

For each vulnerable package identified:

  • Determine if it can be updated in the Dockerfile.
  • Check if a fix is available.
  • Create a plan to address it (e.g., upgrading the base image, upgrading the specific package).

4. Present Plan to User

Present the proposed plan to the user for approval before making changes.

5. Apply Fix and Re-Verify

After making changes to the Dockerfile or related files, repeat Step 1 and Step 2 to publish a new staged image and verify that the vulnerabilities have been resolved.

Mais skills de firebase

developing-genkit-dart
firebase
SDK de IA unificado para Dart que permite geração de código, saídas estruturadas, ferramentas, fluxos e agentes. Fornece APIs principais para geração, definição de ferramentas, orquestração de fluxos, embeddings e streaming com uma única interface. Inclui mais de 8 plugins para provedores de LLM (Google Gemini, Anthropic Claude, OpenAI GPT), Firebase AI, Model Context Protocol, integração com navegador Chrome e hospedagem de servidor HTTP via Shelf. CLI integrado com interface de desenvolvimento local para execução de fluxos, rastreamento, experimentação de modelos e...
official
developing-genkit-js
firebase
Crie aplicativos Node.js/TypeScript com tecnologia de IA usando flows, ferramentas e suporte a múltiplos modelos do Genkit. O Genkit é independente de provedor; suporta Google AI, OpenAI, Anthropic, Ollama e outros provedores de LLM por meio de plugins. Defina flows com esquemas type-safe usando Zod, execute solicitações de geração e componha workflows de IA de várias etapas em TypeScript. Requer Genkit CLI v1.29.0+; mudanças recentes na API significam que você deve consultar genkit docs:read e common-errors.md para padrões atuais, e não conhecimento prévio...
official
extension-to-functions-codebase
firebase
Habilidade para converter uma extensão do Firebase instalada (ou código-fonte da extensão) em um codebase independente do Cloud Functions for Firebase ou em um pacote npm publicável,…
official
firebase-ai-logic
firebase
We need to translate the given text from English to Brazilian Portuguese. The text describes a client-side Gemini integration for web apps. We must preserve the name "firebase-ai-logic" but it's not in the text, so we ignore. We must not add any labels or extra commentary. Just translate the text. The text: "Client-side Gemini integration for web apps with multimodal inference, streaming, and on-device hybrid execution. Supports text-only and multimodal inputs (images, audio, video, PDFs); files over 20 MB route through Cloud Storage Includes chat sessions with automatic history, streaming responses for real-time display, and structured JSON output enforcement Offers hybrid on-device inference via Gemini Nano in Chrome, with automatic fallback to cloud execution Requires App Check for production..." We need to translate accurately, preserving technical terms like "Gemini", "Cloud Storage", "Gemini Nano", "Chrome", "App Check", "JSON", "MB". Also "multimodal inference", "streaming", "on-device hybrid execution", etc. Let's translate:
official
firebase-ai-logic-basics
firebase
Habilidade oficial para integrar o Firebase AI Logic (API Gemini) em aplicações web. Aborda configuração, inferência multimodal, saída estruturada e segurança.
official
firebase-app-hosting-basics
firebase
We need to translate the given text from English to Brazilian Portuguese. The text describes a skill for deploying and managing web apps with Firebase App Hosting. We must preserve product names, protocol names, URLs, numbers, technical terms. The name "firebase-app-hosting-basics" is not in the text, so we don't include it. We translate only the text inside <text>. No extra commentary. Let's translate: "Deploy and manage full-stack web apps with Firebase App Hosting using Next.js, Angular, and other supported frameworks." -> "Implante e gerencie aplicativos web full-stack com o Firebase App Hosting usando Next.js, Angular e outros frameworks compatíveis." "Requires Firebase project on Blaze pricing plan; supports Server-Side Rendering (SSR) and Incremental Static Regeneration (ISR) workflows" -> "Requer projeto Firebase no plano de preços Blaze; suporta fluxos de trabalho de Renderização no Servidor (SSR) e Regeneração Estática Incremental (ISR
official
firebase-auth-basics
firebase
Configure a autenticação do Firebase com vários provedores de identidade e regras seguras de acesso a dados. Suporta email/senha, número de telefone, anônimo, provedores federados (Google, Facebook, Twitter, GitHub, Microsoft, Apple) e integração de autenticação personalizada. Cada usuário autenticado recebe um ID único e tokens baseados em JWT (tokens de ID de curta duração e tokens de atualização de longa duração) para acessar os serviços do Firebase. Ative provedores via CLI para Google Sign In, anônimo e email/senha; use o Firebase Console...
official
firebase-basics
firebase
Configuração de projeto Firebase e fluxo de trabalho da CLI para integração com agente de IA. Requer conclusão prévia da skill firebase-local-env-setup e instalação da Firebase CLI. O fluxo de trabalho principal abrange autenticação via firebase login, criação de projetos com IDs únicos e inicialização de serviços através do comando interativo firebase init. Suporta seleção de recursos durante a configuração, incluindo Firestore, Functions e Hosting, com geração automática de arquivos de configuração. CLI auto-documentada com flags --help para...
official