Hub rules-firebase

rules-firebase

v5 public Verified

Firebase

Firebase is a comprehensive application development platform by Google. These rules assist AI agents in real-time data synchronization, cloud functions, and security rule enforcement for mobile and web apps.

@sigmashakeinc 2 pulls 7 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-firebase →
Severity
5 error 2 warn 0 info
demo.cast
Firebase is a comprehensive application development platform by Google. These rules assist AI agents in real-time data synchronization, cloud functions, and security rule enforcement for mobile and web apps.

Rules index

7 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

firebase

firebase-admin-no-credential warning log

Firebase Admin SDK initialized without explicit credentials — CWE-285. Calling admin.initializeApp() with no arguments relies on Application Default Credentials, which may not be scoped correctly in CI/CD or local dev environments, potentially granting broader permissions than intended. Pass an explicit credential: 'admin.initializeApp({ credential: admin.credential.applicationDefault() })' or a service account credential.

Rule source requires an active Pro or Enterprise subscription.
firebase-deprecated-database-call warning log

firebase.database() uses the compat (v8) Firebase SDK which is deprecated. Migrate to the modular SDK (v9+): import { getDatabase } from 'firebase/database'. The modular SDK is tree-shakeable, receives security patches, and will eventually replace the compat shim.

Rule source requires an active Pro or Enterprise subscription.
firebase-hardcoded-api-key error block

Hardcoded Firebase API key in source — CWE-798. While the Firebase Web API key is technically public-facing, embedding it in committed source alongside a weak security-rules configuration means anyone with the key and no-auth rules can access your data. Store the config in environment variables and keep security rules tight. For server-side usage, never use the Web API key — use a service account credential.

Rule source requires an active Pro or Enterprise subscription.
firebase-open-firestore-read error block

Firestore security rule allows unauthenticated read for all documents — CWE-284. 'allow read: if true' gives every internet user access to the entire collection. Restrict to 'allow read: if request.auth != null' or a more specific condition.

Rule source requires an active Pro or Enterprise subscription.
firebase-open-firestore-write error block

Firestore security rule allows unauthenticated write for all documents — CWE-284. 'allow write: if true' lets anyone on the internet create, modify, or delete any document in the collection. Restrict to authenticated and role-checked writes.

Rule source requires an active Pro or Enterprise subscription.
firebase-open-rtdb-rules error block

Firebase Realtime Database security rule grants unauthenticated access — CWE-284. Setting '.read' or '.write' to literal 'true' at the root exposes the entire database to anonymous reads or writes. Restrict to authenticated users: '"read": "auth != null"'.

Rule source requires an active Pro or Enterprise subscription.
firebase-service-account-in-source error block

Firebase service account private key in source — CWE-798. A committed service account JSON gives any reader full admin access to your Firebase project (Firestore, Auth, Storage, etc.) bypassing all security rules. Remove immediately, rotate the key in Google Cloud IAM, and load credentials from the runtime environment or Secret Manager.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
14c0e5bedaeaeca4ba572d24d8875cbd14b7eceeaec0a192c1305ad93f84f584
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-firebase/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-firebase. The published version only bumps when a maintainer resyncs.

No commit history available.