Move Schematic dependencies to `peerDependencies` or `devDependencies`
- Langage dominant
- TypeScript
- Étoiles
- 7.8k
- Forks
- 2.2k
- Merge moyen
- 22 h 28 min
- PR mergées (30 j)
- 6
Description
### **Description**
In `src/package.json`, `@schematics/angular` and `@angular-devkit/schematics` are currently listed under `dependencies`. Since these packages are only utilized for build-time tasks and schematic generation (found in `src/schematics` and `tools/`), they should not be included in production bundles.
Including them in `dependencies` causes unnecessary bloat and, more critically, pulls in downstream vulnerabilities that wouldn't otherwise affect the production environment.
### **Current Configuration**
```json
"dependencies": {
"firebase": "^12.4.0",
"rxfire": "^6.1.0",
"@angular-devkit/schematics": "^21.0.0", // Move or Remove
"@schematics/angular": "^21.0.0", // Move or Remove
"tslib": "^2.3.0"
},
```
### **Impact: Dependency Vulnerability**
This misconfiguration currently introduces a vulnerability via `picomatch`, which is a sub-dependency of the Angular devkit. Running a production-only dependency check confirms these are being pulled into the prod graph:
```bash
❯ pm why picomatch --prod
Using pnpm
picomatch@4.0.3
├─┬ @angular-devkit/core@21.2.0
│ ├─┬ @angular-devkit/schematics@21.2.0
│ │ └─┬ @schematics/angular@21.2.0
│ │ └─┬ @angular/fire@21.0.0-rc.0
│ │ └── @my-project/source@0.0.0 (dependencies)
│ └── @schematics/angular@21.2.0 [deduped]
└─┬ @angular-devkit/core@21.2.2
└─┬ @angular-devkit/schematics@21.2.2
└── @angular/fire@21.0.0-rc.0 [deduped]
Found 1 version of picomatch
```
### **Proposed Solution**
1. **Remove** `@schematics/angular` and `@angular-devkit/schematics` if they are only needed for generating code in local development. Any Angular project will have them.
2. **Alternatively**, move them to `peerDependencies` (marked as optional if necessary).
Guide de contribution
Ouvrir le guide de contribution
Piste de recherche
Commencez par src/package.json et examinez les références sous src/schematics et tools/ afin de déterminer quel placement des dépendances ces tâches de build nécessitent. Exécutez la pnpm production dependency check indiquée et utilisez pm why picomatch pour comparer le graphe de production. C’est terminé lorsque les paquets schematic ne sont plus inclus dans les dépendances de production et que les tâches locales de génération requises fonctionnent toujours.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- angular, typescript
- Domaine
- build-system, security
- Type d'issue
- Refactorisation
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Activité
- Calme
- Clarté
- Plutôt claire
- Accessibilité débutants
- 52/100