angular / angular/angularfire

Move Schematic dependencies to `peerDependencies` or `devDependencies`

Ouverte
#3,694 1 commentaire 0 réactions 0 personnes assignées Voir sur GitHub
Langage dominant
TypeScript
Étoiles
7.8k
Forks
2.2k
Merge moyen
22 h 28 min
PR mergées (30 j)
6

Description

### **Description**
In `src/package.json`, `@schematics/angular` and `@angular-devkit/schematics` are currently listed under `dependencies`. Since these packages are only utilized for build-time tasks and schematic generation (found in `src/schematics` and `tools/`), they should not be included in production bundles.

Including them in `dependencies` causes unnecessary bloat and, more critically, pulls in downstream vulnerabilities that wouldn't otherwise affect the production environment.

### **Current Configuration**
```json
"dependencies": {
"firebase": "^12.4.0",
"rxfire": "^6.1.0",
"@angular-devkit/schematics": "^21.0.0", // Move or Remove
"@schematics/angular": "^21.0.0", // Move or Remove
"tslib": "^2.3.0"
},
```

### **Impact: Dependency Vulnerability**
This misconfiguration currently introduces a vulnerability via `picomatch`, which is a sub-dependency of the Angular devkit. Running a production-only dependency check confirms these are being pulled into the prod graph:

```bash
❯ pm why picomatch --prod
Using pnpm
picomatch@4.0.3
├─┬ @angular-devkit/core@21.2.0
│ ├─┬ @angular-devkit/schematics@21.2.0
│ │ └─┬ @schematics/angular@21.2.0
│ │ └─┬ @angular/fire@21.0.0-rc.0
│ │ └── @my-project/source@0.0.0 (dependencies)
│ └── @schematics/angular@21.2.0 [deduped]
└─┬ @angular-devkit/core@21.2.2
└─┬ @angular-devkit/schematics@21.2.2
└── @angular/fire@21.0.0-rc.0 [deduped]

Found 1 version of picomatch
```

### **Proposed Solution**
1. **Remove** `@schematics/angular` and `@angular-devkit/schematics` if they are only needed for generating code in local development. Any Angular project will have them.
2. **Alternatively**, move them to `peerDependencies` (marked as optional if necessary).

Guide de contribution

Ouvrir le guide de contribution

Piste de recherche

Commencez par src/package.json et examinez les références sous src/schematics et tools/ afin de déterminer quel placement des dépendances ces tâches de build nécessitent. Exécutez la pnpm production dependency check indiquée et utilisez pm why picomatch pour comparer le graphe de production. C’est terminé lorsque les paquets schematic ne sont plus inclus dans les dépendances de production et que les tâches locales de génération requises fonctionnent toujours.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
angular, typescript
Domaine
build-system, security
Type d'issue
Refactorisation
Difficulté
3/5
Temps estimé
1-2 jours
Activité
Calme
Clarté
Plutôt claire
Accessibilité débutants
52/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.