@firebase/firestorenpm
- latest 4.17.2
- licence Apache-2.0
- stars 5,141
- checked today
- registry ↗
- repository ↗
Vulnerabilities, end of life and next steps
Check a specific version for known advisories, documented mitigations and evidence-backed earlier-version options. Maintenance health is separate from vulnerability status.
Review remediation options →Maintenance trends
Loading historical repository activity…
Signals · last 1 check
The first observation is recorded. Trend lines appear once at least two checks have data for the same signal.
Commits 90d
100
Open issues
452
Unanswered
49
Contributors
19
What the project says about itself
- Build provenance — the latest release carries no provenance attestation. Source: the registry.
- Supported runtime — node >=20.0.0. Source: the registry.
- Publishers on the registry — 4. Source: the registry.
- Open milestones — v12 (due 2025-07-17) 8/8 done. Source: the repository's milestones.
- OpenSSF Scorecard — 7.5 / 10 on 2026-08-24. Source: OpenSSF, via deps.dev. A third party's view of security practice, not part of the health score.
Third-party facts checked today; registry facts on every crawl.
State history 1
| When | Change |
|---|---|
| 2026-09-14 | first verdict: active |
Badge
Drop this in your README. It re-renders itself as the verdict changes.
[](https://isitdeadyet.dev/npm/@firebase/firestore)
Watch it
Get told when @firebase/firestore changes state, changes licence, or is deprecated — instead of finding out during an incident.
Free for up to 25 packages. Signing in is a link sent to your email — there is no password to choose.