angular / angular/angularfire

Move Schematic dependencies to `peerDependencies` or `devDependencies`

Open
#3,694 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
7.8k
Forks
2.2k
Avg merge
22h 28m
Merged PRs (30d)
6

Description

### **Description**
In `src/package.json`, `@schematics/angular` and `@angular-devkit/schematics` are currently listed under `dependencies`. Since these packages are only utilized for build-time tasks and schematic generation (found in `src/schematics` and `tools/`), they should not be included in production bundles.

Including them in `dependencies` causes unnecessary bloat and, more critically, pulls in downstream vulnerabilities that wouldn't otherwise affect the production environment.

### **Current Configuration**
```json
"dependencies": {
"firebase": "^12.4.0",
"rxfire": "^6.1.0",
"@angular-devkit/schematics": "^21.0.0", // Move or Remove
"@schematics/angular": "^21.0.0", // Move or Remove
"tslib": "^2.3.0"
},
```

### **Impact: Dependency Vulnerability**
This misconfiguration currently introduces a vulnerability via `picomatch`, which is a sub-dependency of the Angular devkit. Running a production-only dependency check confirms these are being pulled into the prod graph:

```bash
❯ pm why picomatch --prod
Using pnpm
picomatch@4.0.3
├─┬ @angular-devkit/core@21.2.0
│ ├─┬ @angular-devkit/schematics@21.2.0
│ │ └─┬ @schematics/angular@21.2.0
│ │ └─┬ @angular/fire@21.0.0-rc.0
│ │ └── @my-project/source@0.0.0 (dependencies)
│ └── @schematics/angular@21.2.0 [deduped]
└─┬ @angular-devkit/core@21.2.2
└─┬ @angular-devkit/schematics@21.2.2
└── @angular/fire@21.0.0-rc.0 [deduped]

Found 1 version of picomatch
```

### **Proposed Solution**
1. **Remove** `@schematics/angular` and `@angular-devkit/schematics` if they are only needed for generating code in local development. Any Angular project will have them.
2. **Alternatively**, move them to `peerDependencies` (marked as optional if necessary).

Contributor guide

Open the contributing guide

Research direction

Start with src/package.json and inspect the references under src/schematics and tools/ to determine which dependency placement those build-time tasks require. Run the reported pnpm production dependency check and use pm why picomatch to compare the production graph. Done means the schematic packages are no longer included in production dependencies while the required local generation tasks still work.

Written by the indexing model from the issue text.

Assessment

Tech stack
angular, typescript
Domain
build-system, security
Issue type
Refactor
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.