Skip to content
CAI
Software that uses CAICheck a score

firebase/functions-samples

39.4

Weak · 2 October 2026

13.1k

lines of production code

JavaScript

with Python

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This repository serves as a comprehensive collection of quickstart samples and reference implementations for Firebase Cloud Functions, supporting Node.js, Python, and Dart. It demonstrates serverless logic across various triggers, including HTTP requests, database changes, scheduled tasks, and authentication events, while also showcasing integrations with services like Vertex AI, Jira, and OpenTelemetry. The codebase emphasizes modern development practices by providing updated examples for 2nd-generation function architectures, testing patterns with Jest and Mocha, and codebase-based deployment configurations.

How it got here

2018–2023 — Migration to 2nd Gen and SDK Updates

17 changes.

This period focused on migrating existing Node.js and Python samples to the Firebase Cloud Functions 2nd generation architecture, adopting the new codebase-based deployment model. It also involved updating dependencies to modern runtime versions and SDKs, while introducing new quickstart samples for testing, observability, and specific integrations.

2024–2026 — Firebase Cloud Functions quickstarts

9 changes.

This period focused on expanding the library of Firebase Cloud Functions quickstart samples, introducing new examples for Node.js, Dart, and streaming capabilities. The work emphasized integrating serverless functions with modern AI services like Vertex AI Gemini and Genkit, as well as demonstrating advanced features such as authentication context, remote configuration, and 2nd-generation triggers.

Features

Add 2nd-gen YouTube sample function

Added a new Firebase Cloud Functions (2nd Gen) sample in Node/youtube that queries the YouTube Data API v3. The \getChannelInfo\ callable function retrieves channel metadata (title, description, subscriber count) and the three most recent videos for a specified channel ID, defaulting to the official Firebase channel if none is provided. The sample includes configuration for the Firebase Emulator Suite and requires a \YOUTUBE\_API\_KEY\ secret.

Node/youtube · high confidence

Add Node.js 1st-gen sample codebases

This change introduces a collection of sample applications for Firebase Cloud Functions (1st gen) within the Node-1st-gen directory. The samples include an assistant-say-number action, authenticated JSON APIs, authorized HTTPS endpoints, and data processing templates (BigQuery import, child counting, image conversion). Each sample provides the necessary function code, configuration files (firebase.json, database.rules.json), and public-facing UI assets to demonstrate specific use cases.

Node-1st-gen · high confidence

Add server-side Remote Config sample with Vertex AI Gemini integration

A new Cloud Function sample (\generateWithVertex\) is introduced in the \Node/remote-config-server-with-vertex\ directory, demonstrating how to use Firebase Remote Config to manage Vertex AI Gemini model parameters, safety settings, and feature flags. The function retrieves configuration from Remote Config (such as the model name \gemini-1.5-flash-002\, generation config, and safety thresholds) and uses the \@google-cloud/vertexai\ SDK to stream text responses, allowing users to toggle Vertex AI access via a remote config boolean flag.

Node/remote-config-server-with-vertex · high confidence

Add web client for calling Vertex AI with Remote Config and App Check

A new web client application has been added to demonstrate calling the \callVertexWithRC\ Cloud Function. This client initializes Firebase and App Check (using ReCAPTCHA Enterprise), sends user prompts to the backend function, and renders the Gemini API response as HTML using the Marked library. It includes configuration placeholders for Firebase and ReCAPTCHA keys, supports local emulator testing via Vite, and provides a simple UI with loading indicators and error handling.

Node/call-vertex-remote-config-server/client · high confidence

Added 2nd-gen Cloud Functions quickstart with Mocha testing

A new sample project has been added to demonstrate how to write and run unit tests for 2nd-generation Cloud Functions using Mocha. The sample includes a storage trigger function that logs events, along with a corresponding test file that uses \firebase-functions-test\ to verify the function's behavior.

Node/test-functions-mocha · high confidence

Added Firebase Storage function and tests for logging object finalization

A new Firebase Cloud Function named \logstore\ has been added to the \Node/test-functions-jest-ts/functions\ sample. This function triggers on the \onObjectFinalized\ event for a specified storage bucket and logs the incoming CloudEvent. A corresponding Jest test file has also been added to verify that the function correctly invokes the logger for both default and partial CloudEvent inputs.

Node/test-functions-jest-ts/functions · high confidence

Added Node.js quickstart for testing Gen-2 Firebase Functions with Jest

This location introduces a new sample demonstrating how to unit test Google Cloud Functions for Firebase (Gen-2) using Jest. It includes a storage-triggered function (\onObjectFinalized\) and a corresponding test suite that utilizes \firebase-functions-test\ to wrap and verify the function's behavior, alongside standard configuration files like \firebase.json\ and ESLint rules.

Node/test-functions-jest · high confidence

Added TypeScript and Jest testing quickstart for Gen-2 Functions

This location introduces a new sample project demonstrating how to run unit tests on Gen-2 Cloud Functions using Jest and TypeScript. The addition includes configuration files for the testing environment (jest.config.js, tsconfig.json), linting setup (eslint.config.js), and Firebase project settings (firebase.json) to support a standard development workflow for this specific testing pattern.

Node/test-functions-jest-ts · high confidence

New 2nd Gen Node.js quickstart samples with codebase support

Added new Node.js quickstart samples for custom events, cloud logging, Pub/Sub, Test Lab, Firestore, and Realtime Database. These samples use the 2nd generation Cloud Functions SDK (e.g., \onCustomEventPublished\, \onMessagePublished\, \onDocumentCreated\) and are configured with distinct \codebase\ entries in \firebase.json\ to support the new codebase-based deployment model.

(repo-wide) · high confidence

New 2nd-gen Auth-triggered Cloud Functions quickstart for email notifications

Added a new Node.js quickstart in \Node/quickstarts/email-users\ that demonstrates 2nd-generation Firebase Auth-triggered Cloud Functions. The sample implements \onUserCreated\ and \onUserDeleted\ triggers to send welcome and goodbye emails via the Resend API, including multi-tenancy examples that scope triggers to specific Identity Platform tenants or non-tenant users.

Node/quickstarts/email-users · high confidence

New Dart quickstart samples for Firebase Cloud Functions

Added Dart-language quickstart examples for Firebase Cloud Functions, including an HTTPS time-server, callable functions (standard and streaming), and an image-resize optimizer. These samples demonstrate how to define and deploy Dart functions, handle HTTP requests and query parameters, stream responses, and integrate with Cloud Storage.

Dart · high confidence

New Firebase Functions samples for Jira feedback and Remote Config diffs

Added two new sample projects: \app-distribution-feedback-to-jira\ and \remote-config-diff\. The Jira sample demonstrates a Cloud Function that triggers on in-app feedback alerts from Firebase App Distribution, creating issues in Jira (including screenshot attachments) using parameterized configuration and secret management. The Remote Config sample shows how to use the \onConfigUpdated\ trigger to fetch and log the difference between the current and previous Remote Config templates using the \json-diff\ library.

Node/app-distribution-feedback-to-jira, Node/remote-config-diff · high confidence

New Firestore sync with auth context quickstart

Added a new Node.js quickstart sample that demonstrates using the Firebase SDK for Cloud Functions with Firestore and authentication context. The sample includes a Cloud Function (\verifyComment\) triggered by document writes, which extracts the \authType\ and \authId\ from the event to determine if a user is verified (e.g., system users or specific admin domains) and updates the Firestore document with \created\_by\ and \verified\ metadata. The entry also includes necessary configuration files (\firebase.json\, \firestore.rules\, \firestore.indexes.json\) and a README with instructions for running the sample locally using the Firebase Emulator Suite or deploying to a live project.

Node/quickstarts/firestore-sync-auth · high confidence

New Genkit quickstart sample for streaming Cloud Functions

Added a new quickstart sample in Node/quickstarts/genkit-helloworld that demonstrates initializing a Genkit flow and serving it via Cloud Functions for Firebase. The sample implements a 'tellJoke' function using the onCallGenkit trigger, which streams responses from the Gemini 1.5 Flash model via Google AI. It includes configuration for Firebase functions, ESLint, and environment variables, providing a complete example of integrating Genkit with Firebase's serverless platform.

Node/quickstarts/genkit-helloworld · high confidence

New callable function to integrate Firebase Remote Config with Vertex AI

A new callable Cloud Function, \callVertexWithRC\, has been added to the Remote Config server sample. This function allows users to dynamically configure Vertex AI parameters (such as model name, location, safety settings, and generation config) via Firebase Remote Config. It accepts a user prompt, combines it with the configured system prompt, and streams the response from the specified Gemini model back to the client, with optional App Check enforcement.

Node/call-vertex-remote-config-server/functions · high confidence

New quickstart demonstrating streaming responses in Firebase Callable Functions

Added a new sample project that demonstrates how to implement and consume streaming responses using Firebase HTTPS Callable functions. The server-side implementation in \functions/index.js\ uses \response.sendChunk()\ to stream individual weather forecast results as they become available, while the client-side UI in \website/index.html\ utilizes the new \.stream()\ method on the callable to update the interface incrementally as each chunk arrives.

Node/quickstarts/callable-functions-streaming · high confidence

New samples for OpenTelemetry instrumentation and Cloud Storage thumbnail generation

Added two new Node.js quickstart samples. The \instrument-with-opentelemetry\ sample demonstrates how to instrument Firebase Cloud Functions with OpenTelemetry to export traces to Google Cloud Trace, including automatic instrumentation for HTTP, gRPC, and Express, as well as manual span creation. The \quickstarts/thumbnails\ sample shows how to use the v2 Cloud Storage trigger (\onObjectFinalized\) to automatically generate image thumbnails using the \sharp\ library when files are uploaded to a Storage bucket.

Node/instrument-with-opentelemetry, Node/quickstarts/thumbnails · high confidence

Behavioural changes

Callable functions quickstart updated to use v2 SDK and new sanitization logic

The callable functions quickstart has been updated to use the v2 \firebase-functions/https\ SDK, replacing the previous v1 imports. The \addmessage\ function now explicitly checks for user authentication via \request.auth\ before saving messages to the Realtime Database. Additionally, the text sanitization logic in \sanitizer.js\ has been modified to remove the previous behavior of auto-capitalizing sentences when users 'shout', while retaining the filtering of swearwords using the \bad-words\ library.

Node/quickstarts/callable-functions/functions · high confidence

HTTPS time-server quickstart updated to Firebase Functions v2

The HTTPS time-server quickstart has been migrated to the Firebase Functions v2 SDK, replacing the previous v1 imports with the \firebase-functions/https\ module. This change introduces support for specifying multiple deployment regions (us-west1, us-east1) and increases the default timeout to 1200 seconds. The sample function now returns the current server date, accepting a date format string via URL query parameters or the request body, while explicitly rejecting PUT requests with a 403 error. Configuration files for the Firebase CLI and ESLint have also been added to support this 2nd-gen architecture.

Node/quickstarts/https-time-server · high confidence

Image backup function migrated to Firebase Functions v2 with task queues

The Node.js function in this directory has been updated to use the Firebase Functions v2 runtime, replacing the previous v1 imports with the new \firebase-functions/tasks\ and \firebase-functions/https\ modules. This change introduces support for task queues, allowing the \backupapod\ function to be dispatched asynchronously with configurable retry policies and rate limits, while the \enqueuebackuptasks\ function now schedules these tasks using the v2 API. The implementation also switches HTTP client usage from external libraries to the native \fetch\ API and includes a new ESLint configuration to relax strict linting rules for this snippet.

Node/taskqueues-backup-images/functions · high confidence

Python samples migrated to 2nd generation Cloud Functions

The Python samples have been updated to use the 2nd generation Cloud Functions for Firebase SDK. This introduces a new API surface, including dedicated trigger modules for alerts (Crashlytics, App Distribution, Performance), database, HTTP, and scheduled events, as well as support for auth blocking functions and task queues. The samples now utilize the \firebase\_functions\ package and are organized into distinct codebases, requiring an update to existing Python function code to align with the new generation's structure and capabilities.

Python · high confidence

Sample updated to use Firebase Functions 2nd gen and Cloud Scheduler

The delete-unused-accounts-cron sample has been migrated to the 2nd generation of Firebase Cloud Functions. It now uses the \firebase-functions/scheduler\ API with \onSchedule\ to trigger the account cleanup job daily at midnight, replacing the previous implementation. The configuration includes a \firebase.json\ file defining a specific codebase for the function, and the code utilizes the Firebase Admin SDK to list and delete inactive users with controlled concurrency.

Node/delete-unused-accounts-cron · high confidence

Updated FCM notifications sample to use Firebase Functions v2 and modern SDKs

The FCM notifications sample has been updated to use the Firebase Functions v2 API (specifically \onValueWritten\) and the modular Firebase Admin SDK, replacing the older v1 syntax. The web client now uses Firebase SDK version 10.0.0, and the project includes updated configuration files (firebase.json, database.rules.json) and a new ESLint configuration to support the modern codebase.

Node/fcm-notifications · high confidence

Updated Firebase Cloud Functions samples to 2nd-gen architecture

The alerts-to-discord and testlab-to-slack samples have been migrated to Firebase Cloud Functions 2nd generation. This update replaces the previous v1 imports with the new v2 alert and test lab triggers, switches HTTP client usage from axios/node-fetch to the native fetch API, and configures the functions to use the new codebase-based deployment structure defined in firebase.json.

Node/alerts-to-discord, Node/testlab-to-slack · high confidence

Updated auth-blocking-functions quickstart to Firebase Functions 2nd Gen

The auth-blocking-functions sample has been migrated to Firebase Cloud Functions 2nd Gen, updating the implementation to use the \firebase-functions/identity\ API for blocking account creation, sign-in, email sending, and SMS sending. The sample now includes a \firebase.json\ configuration with a dedicated codebase and enforces linting via ESLint before deployment, ensuring the code follows modern standards for Firebase Auth extension points.

Node/quickstarts/auth-blocking-functions · high confidence

Dependencies

Update Node.js samples to Firebase Functions v7 and Node 22

The Node.js 1st-generation sample functions have been updated to use \firebase-functions\ version 7.3.2 and \firebase-admin\ version 14.2.0, with the runtime engine set to Node 22. Additionally, Dart quickstart samples for callable and HTTPS functions have been added, utilizing the \firebase\_functions\ SDK version 0.6.0 and Dart SDK 3.11.0.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 41 → 39 (-1.1)
  • Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.

Lenses

  • Code Health 68 → 93 (+25.1)
  • Architecture 96 → 97 (+1.4)
  • Maturity 61 → 61 (+0.2)
  • Readiness 32 → 27 (-5.1)
  • Security 53 → 59 (+6.0)
  • Accessibility 33 → 33 (+0.2)
  • Performance 60 (new)

Resolved (41)

  • Documentation: no installation or build instructions (Node/call-vertex-remote-config-server/README.md)
  • Documentation: no installation or build instructions (Node/delete-unused-accounts-cron/README.md)
  • Documentation: no installation or build instructions (Node/instrument-with-opentelemetry/README.md)
  • Documentation: no installation or build instructions (README.md)
  • Documentation: no usage examples (README.md)
  • High CVE: [GHSA redacted] (Node-1st-gen/assistant-say-number/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/assistant-say-number/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/delete-old-child-nodes/functions/pnpm-lock.yaml)
  • Low CVE: [GHSA redacted] (Node-1st-gen/instagram-auth/functions/pnpm-lock.yaml)
  • Off-boarding risk: anonymized user #1
  • Outdated (npm): @babel/runtime
  • Outdated (npm): @elastic/elasticsearch
  • Outdated (npm): @firebase/functions
  • Outdated (npm): @google-cloud/bigquery
  • Outdated (npm): @google-cloud/language
  • Outdated (npm): @google-cloud/logging
  • Outdated (npm): @google-cloud/opentelemetry-cloud-trace-exporter
  • Outdated (npm): @google-cloud/opentelemetry-cloud-trace-propagator
  • Outdated (npm): @google-cloud/storage
  • Outdated (npm): @google-cloud/translate
  • …and 21 more

New (12)

  • Dependency hygiene PARTLY measured — Python dependencies read, no exact pin to grade for currency
  • High CVE: [GHSA redacted] (Node-1st-gen/fulltext-search-firestore/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/instagram-auth/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/assistant-say-number/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/assistant-say-number/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/delete-old-child-nodes/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/assistant-say-number/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/assistant-say-number/functions/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node/call-vertex-remote-config-server/client/pnpm-lock.yaml)
  • High CVE: [GHSA redacted] (Node-1st-gen/fulltext-search-firestore/functions/pnpm-lock.yaml)
  • Medium CVE: [GHSA redacted] (Node-1st-gen/quickstarts/https-time-server/functions/pnpm-lock.yaml)
  • Off-boarding risk: anonymized user #1

Changes since last survey

  • 5 commits — 2 feature/other, 3 fixes

By area

  • Node-1st-gen/fulltext-search-firestore — 2 commits
  • Node-1st-gen/delete-unused-accounts-cron — 1 commit
  • Node-1st-gen/moderate-images — 1 commit
  • Node/quickstarts — 1 commit

Notable commits

  • fix: fix delete-unused-accounts-cron crash from es6-promise-pool .default (#1320)
  • fix: fix(fulltext-search-firestore): require auth and filter by owner in elastic searchNotes (#1316)
  • fix: fix(moderate-images): use execFile in blurImage (#1317)
  • change: Re-enable typechecking (#1313)
  • change: update 2nd gen auth sample to use latest prod functions SDK (#1314)

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

firebase/functions-samples was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9270a706434f17dcb3a7dac26649b94d3771223a — the exact code this score is about.
  • Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.