Releases: angular/angularfire
Release list
20.1.0
What's Changed
- feat:
ng add @angular/firenow writes the Firebase project files a new app needs. Selecting Firestore generates a.firebaserccarrying your selected project, afirestore.rulesfile, and afirestore.indexes.json, so the project is deployable without hand-writing them. by @armando-navarro in #3714 - fix:
ng add @angular/fireexplains itself when nothing is selected. Confirming the feature checklist with no features chosen previously ended the setup silently, as if it had worked. It now prints what happened and how to select features on a re-run. by @armando-navarro in #3717
A note on the generated Firestore rules
The firestore.rules file that ng add writes is Firebase's standard test-mode starter: it allows anyone read and write access to your database, and the rule is written to expire 30 days after generation, after which all client requests are denied. Write real security rules for your app before that date. See Firestore security rules.
Full Changelog: 20.0.3...20.1.0
21.0.0-rc.1
What's Changed
Upgrading to v21
- fix:
ng update @angular/fireupdates your project'sfirebasedependency to the supported^12.18.0, andng addaligns it during setup, preventing duplicated-SDK installs by @armando-navarro in #3722 - fix: require rxfire 6.2.0 or newer. Older rxfire versions ask for firebase 11, which can install a second Firebase SDK copy next to your firebase 12. by @armando-navarro in #3723
- build: require firebase 12.18.0 or newer. AngularFire wraps four new Cloud Messaging functions:
onRegistered,onUnregistered,registerandunregister. by @armando-navarro in #3761 - build: require Angular 21.2 or newer. Angular 21 is in long-term support, which ships only critical fixes and security patches, so 21.2 is the final 21.x minor line. Projects still on Angular 21.0 or 21.1 should run
ng update @angular/core @angular/clibefore updating AngularFire. by @armando-navarro in #3763 - fix: drop the
@angular/fire/aiimport of the removed Imagen API, which made fresh installs fail to build against firebase 12.18.0.ng updatewarns remaining Imagen users with migration guidance. by @armando-navarro in #3750 - feat:
ng update @angular/firerewrites imports from the removed Vertex AI module to its replacement,@angular/fire/ai(Firebase AI Logic), including the renamed symbols, and a new guide covers upgrading from AngularFire 20 to 21 by @armando-navarro in #3725 - fix:
ng update @angular/fireusesAgentPlatformBackendinstead of the deprecatedVertexAIBackend. Location defaults toglobalinstead ofus-central1. The migration warns for every file whose region changed. by @armando-navarro in #3762
Setting up (ng add)
- feat:
ng add @angular/firewarns when multiple versions of firebase are installed, and shows the dependency chain. Prevents various hard-to-diagnose bugs. by @armando-navarro in #3760 - fix:
ng addgenerates working@angular/fire/aiimports when the AI feature is selected, instead of imports from a removed module path. Docs updated to use the Firebase AI Logic naming. by @coturiv in #3685 - fix: remove the
@angular/platform-browser-dynamicpeer dependency, which madeng add @angular/firefail withERESOLVEon Angular 20.1 and newer. by @armando-navarro in #3718 - fix:
ng addwrites only accepted keys into the app config, which previously did not compile. The whole Firebase CLI response was inlined intoinitializeApp(), including management fields such asprojectNumberthatFirebaseOptionsrejects, producingTS2769. by @armando-navarro in #3707 - feat:
ng add @angular/fireand selecting Firestore generates a.firebasercfile, afirestore.rulesfile, and afirestore.indexes.jsonfile. by @armando-navarro in #3714 - fix:
ng add @angular/fire@nextrecords prerelease installs as the exact installed version. Prevents later installs replacing your chosen AngularFire release candidate. by @armando-navarro in #3709 - fix:
ng add @angular/fireprints a helpful message when no features are selected. Previously, the setup ended silently, as if it had worked. by @armando-navarro in #3717 - fix: log the caught error when
dataconnect.yamlparsing fails, instead of discarding it by @armando-navarro in #3711 - fix: accept firebase-tools 15. Eliminates peer dependency warnings on install for projects on the current Firebase CLI. by @armando-navarro in #3702
- fix: update the firebase-tools version check error message. by @Muneersahel in #3662
Deploying (ng deploy)
- fix:
ng deployno longer crashes on launch withERR_INVALID_ARG_TYPE. The schematics ship as a CommonJS bundle, which turned the code'simport.metalookup intoundefinedbefore it reached any real work. by @armando-navarro in #3729 - fix: the Cloud Function generated for SSR now asks for Node 22, instead of Node 14, a runtime Cloud Functions decommissioned in early 2025. by @armando-navarro in #3743
- fix: the generated Cloud Function imports
regionfrom thefirebase-functions/v1subpath, where firebase-functions 6 moved it. Calling it from the package root threw on the function's first request. by @armando-navarro in #3743 - fix: the Cloud Function generated for SSR now uses a public firebase-functions logger entry point, instead of an internal path that crashed the function at startup by @armando-navarro in #3730
- fix: the
package.jsongenerated for SSR deployments declaresfirebase-adminwith a real, installable range. It was omitted even though firebase-functions requires it at load time, so the deployed function could crash withCannot find module 'firebase-admin/app-check'. by @armando-navarro in #3745 - fix: declare the three packages the schematics require at runtime (
jsonc-parser,@angular-devkit/core,@angular-devkit/architect). The publishedpackage.jsonnever listed them, song deployfailed to resolve modules under pnpm's default layout and Yarn Plug'n'Play. by @armando-navarro in #3747 - fix:
ng deploywrites the generated entry paths with forward slashes regardless of the deploying machine. Running it from Windows with the Cloud Run SSR option wrote backslash paths, which the Linux-based Cloud Run runtime cannot resolve. by @fr-esco in #3274
Security hardening
- fix:
ng deployno longer places values read fromangular.jsoninto shell commands, closing a command-injection hole by @herdiyana256 in #3738 - fix: the code and Dockerfile that
ng deploygenerates for SSR now escape or validate theangular.jsonvalues they interpolate (output path, function name, Node version). A crafted value could previously place arbitrary code in the generated files. by @herdiyana256 in #3739 - fix:
ng deploypasses gcloud arguments as an array. It previously built the command as one string and re-split it on whitespace, so a deploy option containing a space (a region, project, or function name fromangular.json) could smuggle extra flags into thegcloudinvocation. by @herdiyana256 in #3726 - fix: the
provideDataConnect(...)call thatng addgenerates escapes the values it takes from yourdataconnect.yaml/connector.yaml. A value containing a quote character could previously place arbitrary code in the generated file. by @herdiyana256 in #3727
CI and repository health
- ci: upgrade the Java version used by the test emulators from 11 to 21. Current firebase-tools requires Java 21 or newer, so every emulator-backed CI job had been failing at emulator startup. This change is what turned the repo's test pipeline green again. by @mwilman in #3687
- ci: resolve the zizmor security findings in the GitHub Actions workflows by @jhuleatt in #3700
Documentation
- docs: the quickstart and README match what
ng addactually does today, with current scaffold names, the Firebase Hosting and App Hosting deploy paths, and the prerequisites called out up front by @armando-navarro in #3736 - docs: the auth guide's Server-side Rendering section is rewritten around a verified working setup. The old snippet did not compile, and each of the four required steps explains what silently breaks without it. by @armando-navarro in #3740
- docs: new guide, Deploying SSR to App Hosting, including how to detect and fix the silent fallback to client-side rendering by @armando-navarro in #3720
- docs: new Data Connect guide, linked from the README feature table by @armando-navarro in #3724
- docs: new injection-context recipe showing how to keep AngularFire calls in an injection context in async code by @armando-navarro in #3721
- docs: the copy-paste samples in the product guides compile as written again by @armando-navarro in #3732
- docs: fix stale links and grammar, remove obsolete doc files by @armando-navarro in #3734
- docs: log the token value in the auth
idTokenexample by @armando-navarro in #3728 - docs: import the pipes correctly in the route-guard examples by @Erick2280 in #3623
- docs: the auth guide's
user$example references the injectedthis.authby @arolleagueken...
20.0.3
What's Changed
- fix: remove the
@angular/platform-browser-dynamicpeer dependency, which madeng add @angular/firefail withERESOLVEon Angular 20.1 and newer. It forced npm toward a version whose own requirements clashed with the app's, and nothing in the published package imports it. by @armando-navarro in #3718 - fix:
ng addnow writes only accepted keys into the app config, which previously did not compile. The whole Firebase CLI response was inlined intoinitializeApp(), including management fields such asprojectNumberthatFirebaseOptionsrejects, producingTS2769. by @armando-navarro in #3707 - fix: accept firebase-tools 15. The optional peer dependency was capped at
^14.0.0, which excluded the current major, so anyone on the current Firebase CLI saw peer dependency warnings on every install. The range is now^14.0.0 || ^15.0.0. by @armando-navarro in #3702 - fix: the firebase-tools version check now asks for the version it enforces. It said 13.0.0 or newer while actually requiring 14.0.0 or newer. by @Muneersahel in #3662
- fix: the Cloud Function generated for SSR now uses a public firebase-functions logger entry point, instead of an internal path that crashed the function at startup. by @armando-navarro in #3730
- fix: the
package.jsongenerated for SSR deployments now carries real version ranges forfirebase-adminandfirebase-functions. Both were pinned to the placeholder0.0.0, sonpm installcould not resolve them and failed withETARGET. by @armando-navarro in #3745 - fix: the generated Cloud Function now asks for Node 22, instead of Node 14, a runtime Cloud Functions decommissioned in early 2025. by @armando-navarro in #3743
- fix: the generated Cloud Function now imports
regionfrom thefirebase-functions/v1subpath, where firebase-functions 6 moved it. Calling it from the package root threw on the function's first request. by @armando-navarro in #3743 - ci: upgrade the Java version used by the test emulators from 11 to 21 by @mwilman in #3687
New Contributors
- @Muneersahel made their first contribution in #3662
- @mwilman made their first contribution in #3687
A note on ng deploy with SSR
The last three fixes repair defects in the Cloud Function that ng deploy generates, but they do not make SSR deployment to Cloud Functions work end to end on a project created with Angular 17 or newer. That command still looks for a server build target which the current Angular application builder does not create.
If you are deploying a server-side rendered Angular app to Firebase today, App Hosting is the supported path. Plain ng deploy without SSR is unaffected.
Full Changelog: 20.0.1...20.0.3
21.0.0-rc.0
What's Changed
- Bump all Angular dependencies to
^21.0.0build to~0.2100.0 - Bump firebase to next major
- Drop vertexai
- Lots of lint and tsconfig drama
- Unbork Github Actions
I fully expect I broke something, there were a lot of build / lint issues with this major. Just need to get the ball rolling here now that all the deps are out. Will publish an update to rxfire to fix the peer conflict.
Full Changelog: 20.0.1...21.0.0-rc.0
20.0.1
20.0.0
20.0.0-rc.0
19.2.0
19.1.0
19.0.0
What's Changed
- Single sample application—demonstrating the modular SDK in a Zoneless SSR application with code-splitting on
@defer - Now logging zone warnings about instability when using AngularFire outside of an injection context
- Added docs on application instability
- Bumped Angular, Firebase, and other dependencies
- Now bundling CLI dependencies
Added
- Support for Angular v19
- Support for Zoneless Angular applications
- Add
setLogLevelto control Zone log verbosity @angular/fire/data-connectentry point
Breaks
- Dropped
BlockUntilFirstOperatorandkeepUnstableUntilFirstin favor of Angular'sPendingTasksandpendingUntilEvent, this should only be an improvement but requires AngularFire APIs be called in an Injection Context to be able to zone-wrap properly ZoneWrapperand other AngularFire providers are no longer singletons, this allows better functionality with concurrent SSR- Drop
isSupportedinjection hack in favor of testing Angular'sPLATFORM_ID, this shouldn't affect most developers but you may need to manually checkisSupportedif you're targeting browsers that don't support Firebase SDKs e.g, Messaging on older versions of Safari - Renamed
vertex-previewentry tovertex
New Contributors
- @mmalerba made their first contribution in #3543
- @DellaBitta made their first contribution in #3570
- @hsubox76 made their first contribution in #3577
- @rosostolato made their first contribution in #3595
Full Changelog: 18.0.1...19.0.0