Skip to content

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot - #8856

Merged
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides
Jun 16, 2026
Merged

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot#8856
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Most of the open Dependabot alerts on this repo trace to dev tooling, build toolchains, or lazily-loaded web3 wallet transitives that never reach customer runtime. This clears the ones worth clearing with range-scoped pnpm.overrides plus a few dev-tooling bumps.

The only change that touches a published artifact is preact 10.27.2 → 10.27.3 inside clerk-js's lazily-loaded Coinbase wallet chunk, which is why the clerk-js patch changeset is here. The happy-dom 18 → 20 bump in @clerk/headless is the other thing worth a glance; its tests stay green (403 passing).

esbuild and webpack are deliberately left out: esbuild's patch is still inside the 3-day release-age window, and a webpack bump drags its entire @webassemblyjs tree for a low-severity, build-only advisory. Both can ride the normal Renovate flow. Lockfile was regenerated with pnpm dedupe.

Summary by CodeRabbit

  • Chores
    • Updated development dependencies including test framework (vitest), coverage tools, and test environment (happy-dom)
    • Upgraded react-router to the latest available version
    • Updated preact bundled version for Coinbase Wallet integration support
    • Expanded pnpm dependency version overrides and constraints across multiple packages

…abot
Range-scoped pnpm.overrides for transitive advisories that don't reach
customer runtime (axios, jws, tmp, minimatch, picomatch, svgo, fast-uri,
ip-address, flatted, follow-redirects, smol-toml, socket.io-parser,
@babel/plugin-transform-modules-systemjs), the one shipped fix (preact
10.27.3 in clerk-js's lazy Coinbase wallet chunk), and dev-tooling bumps
(vitest 3.2.6/4.1.6, happy-dom 20, react-router 7.15.0).
@changeset-bot

changeset-botBot commented Jun 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c30dcc9

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 14, 2026 2:05am
swingsetReadyReadyPreview, CommentJun 14, 2026 2:05am

Request Review

@coderabbitai

coderabbitaiBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: b4222c80-c982-4c21-9606-9dda68ccc17f

📥 Commits

Reviewing files that changed from the base of the PR and between d46f262 and ff82a6a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .changeset/clerk-js-coinbase-preact-patch.md
  • package.json
  • packages/headless/package.json
  • packages/react-router/package.json

📝 Walkthrough

Walkthrough

This PR updates dependency versions and pnpm override constraints across the Clerk JavaScript monorepo. A patch release for @clerk/clerk-js documents the preact version bundled in the Coinbase Wallet web3 chunk being updated to 10.27.3. Root dev dependencies and workspace-enforced version constraints are bumped, and individual workspace packages receive targeted dev dependency updates.

Changes

Dependency and version constraint updates

Layer / File(s)Summary
Preact bundling changelog
.changeset/clerk-js-coinbase-preact-patch.md
Changesets entry declares a patch release for @clerk/clerk-js noting that the Coinbase Wallet web3 chunk's bundled preact version was updated to 10.27.3.
Root package dependency and constraint updates
package.json
Root devDependencies bumps @vitest/coverage-v8 and vitest from 3.2.4 to 3.2.6. pnpm.overrides is extended with version constraints for @babel/plugin-transform-modules-systemjs, axios, fast-uri, flatted, follow-redirects, ip-address, jws, minimatch, picomatch, preact, semver, smol-toml, socket.io-parser, svgo, and tmp.
Workspace package dev dependency updates
packages/headless/package.json, packages/react-router/package.json
happy-dom bumped from ^18.0.1 to ^20.8.9 and vitest bumped from 4.1.4 to 4.1.6 in headless. react-router bumped from 7.14.2 to 7.15.0 in react-router.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested labels

clerk-js

Suggested reviewers

  • dstaley
  • wobsoriano

Poem

🐰 Preact hops to ten-point-three,
vitest patches flow so free,
Dependencies align with care,
Happy-dom climbs high in air,
React-router takes the lead—updates complete!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and specifically describes the main change: patching vulnerable transitive dependencies flagged by Dependabot.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Jun 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8856

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8856

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8856

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8856

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8856

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8856

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8856

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8856

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8856

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8856

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8856

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8856

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8856

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8856

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8856

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8856

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8856

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8856

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8856

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8856

commit: c30dcc9

@github-actions

github-actionsBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-14T02:05:52.536Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on c30dcc9.

@jacekradko
jacekradko merged commit cc83980 into mainJun 16, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/dependabot-transitive-overrides branch June 16, 2026 13:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
fix(repo): patch vulnerable transitive dependencies flagged by Dependabot by jacekradko · Pull Request #8856 · clerk/javascript · GitHub
Skip to content

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot - #8856

Merged
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides
Jun 16, 2026
Merged

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot#8856
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Most of the open Dependabot alerts on this repo trace to dev tooling, build toolchains, or lazily-loaded web3 wallet transitives that never reach customer runtime. This clears the ones worth clearing with range-scoped pnpm.overrides plus a few dev-tooling bumps.

The only change that touches a published artifact is preact 10.27.2 → 10.27.3 inside clerk-js's lazily-loaded Coinbase wallet chunk, which is why the clerk-js patch changeset is here. The happy-dom 18 → 20 bump in @clerk/headless is the other thing worth a glance; its tests stay green (403 passing).

esbuild and webpack are deliberately left out: esbuild's patch is still inside the 3-day release-age window, and a webpack bump drags its entire @webassemblyjs tree for a low-severity, build-only advisory. Both can ride the normal Renovate flow. Lockfile was regenerated with pnpm dedupe.

Summary by CodeRabbit

  • Chores
    • Updated development dependencies including test framework (vitest), coverage tools, and test environment (happy-dom)
    • Upgraded react-router to the latest available version
    • Updated preact bundled version for Coinbase Wallet integration support
    • Expanded pnpm dependency version overrides and constraints across multiple packages

…abot
Range-scoped pnpm.overrides for transitive advisories that don't reach
customer runtime (axios, jws, tmp, minimatch, picomatch, svgo, fast-uri,
ip-address, flatted, follow-redirects, smol-toml, socket.io-parser,
@babel/plugin-transform-modules-systemjs), the one shipped fix (preact
10.27.3 in clerk-js's lazy Coinbase wallet chunk), and dev-tooling bumps
(vitest 3.2.6/4.1.6, happy-dom 20, react-router 7.15.0).
@changeset-bot

changeset-botBot commented Jun 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c30dcc9

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 14, 2026 2:05am
swingsetReadyReadyPreview, CommentJun 14, 2026 2:05am

Request Review

@coderabbitai

coderabbitaiBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: b4222c80-c982-4c21-9606-9dda68ccc17f

📥 Commits

Reviewing files that changed from the base of the PR and between d46f262 and ff82a6a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .changeset/clerk-js-coinbase-preact-patch.md
  • package.json
  • packages/headless/package.json
  • packages/react-router/package.json

📝 Walkthrough

Walkthrough

This PR updates dependency versions and pnpm override constraints across the Clerk JavaScript monorepo. A patch release for @clerk/clerk-js documents the preact version bundled in the Coinbase Wallet web3 chunk being updated to 10.27.3. Root dev dependencies and workspace-enforced version constraints are bumped, and individual workspace packages receive targeted dev dependency updates.

Changes

Dependency and version constraint updates

Layer / File(s)Summary
Preact bundling changelog
.changeset/clerk-js-coinbase-preact-patch.md
Changesets entry declares a patch release for @clerk/clerk-js noting that the Coinbase Wallet web3 chunk's bundled preact version was updated to 10.27.3.
Root package dependency and constraint updates
package.json
Root devDependencies bumps @vitest/coverage-v8 and vitest from 3.2.4 to 3.2.6. pnpm.overrides is extended with version constraints for @babel/plugin-transform-modules-systemjs, axios, fast-uri, flatted, follow-redirects, ip-address, jws, minimatch, picomatch, preact, semver, smol-toml, socket.io-parser, svgo, and tmp.
Workspace package dev dependency updates
packages/headless/package.json, packages/react-router/package.json
happy-dom bumped from ^18.0.1 to ^20.8.9 and vitest bumped from 4.1.4 to 4.1.6 in headless. react-router bumped from 7.14.2 to 7.15.0 in react-router.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested labels

clerk-js

Suggested reviewers

  • dstaley
  • wobsoriano

Poem

🐰 Preact hops to ten-point-three,
vitest patches flow so free,
Dependencies align with care,
Happy-dom climbs high in air,
React-router takes the lead—updates complete!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and specifically describes the main change: patching vulnerable transitive dependencies flagged by Dependabot.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Jun 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8856

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8856

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8856

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8856

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8856

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8856

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8856

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8856

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8856

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8856

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8856

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8856

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8856

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8856

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8856

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8856

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8856

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8856

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8856

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8856

commit: c30dcc9

@github-actions

github-actionsBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-14T02:05:52.536Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on c30dcc9.

@jacekradko
jacekradko merged commit cc83980 into mainJun 16, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/dependabot-transitive-overrides branch June 16, 2026 13:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(repo): patch vulnerable transitive dependencies flagged by Dependabot by jacekradko · Pull Request #8856 · clerk/javascript · GitHub
Skip to content

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot - #8856

Merged
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides
Jun 16, 2026
Merged

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot#8856
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Most of the open Dependabot alerts on this repo trace to dev tooling, build toolchains, or lazily-loaded web3 wallet transitives that never reach customer runtime. This clears the ones worth clearing with range-scoped pnpm.overrides plus a few dev-tooling bumps.

The only change that touches a published artifact is preact 10.27.2 → 10.27.3 inside clerk-js's lazily-loaded Coinbase wallet chunk, which is why the clerk-js patch changeset is here. The happy-dom 18 → 20 bump in @clerk/headless is the other thing worth a glance; its tests stay green (403 passing).

esbuild and webpack are deliberately left out: esbuild's patch is still inside the 3-day release-age window, and a webpack bump drags its entire @webassemblyjs tree for a low-severity, build-only advisory. Both can ride the normal Renovate flow. Lockfile was regenerated with pnpm dedupe.

Summary by CodeRabbit

  • Chores
    • Updated development dependencies including test framework (vitest), coverage tools, and test environment (happy-dom)
    • Upgraded react-router to the latest available version
    • Updated preact bundled version for Coinbase Wallet integration support
    • Expanded pnpm dependency version overrides and constraints across multiple packages

…abot
Range-scoped pnpm.overrides for transitive advisories that don't reach
customer runtime (axios, jws, tmp, minimatch, picomatch, svgo, fast-uri,
ip-address, flatted, follow-redirects, smol-toml, socket.io-parser,
@babel/plugin-transform-modules-systemjs), the one shipped fix (preact
10.27.3 in clerk-js's lazy Coinbase wallet chunk), and dev-tooling bumps
(vitest 3.2.6/4.1.6, happy-dom 20, react-router 7.15.0).
@changeset-bot

changeset-botBot commented Jun 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c30dcc9

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 14, 2026 2:05am
swingsetReadyReadyPreview, CommentJun 14, 2026 2:05am

Request Review

@coderabbitai

coderabbitaiBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: b4222c80-c982-4c21-9606-9dda68ccc17f

📥 Commits

Reviewing files that changed from the base of the PR and between d46f262 and ff82a6a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .changeset/clerk-js-coinbase-preact-patch.md
  • package.json
  • packages/headless/package.json
  • packages/react-router/package.json

📝 Walkthrough

Walkthrough

This PR updates dependency versions and pnpm override constraints across the Clerk JavaScript monorepo. A patch release for @clerk/clerk-js documents the preact version bundled in the Coinbase Wallet web3 chunk being updated to 10.27.3. Root dev dependencies and workspace-enforced version constraints are bumped, and individual workspace packages receive targeted dev dependency updates.

Changes

Dependency and version constraint updates

Layer / File(s)Summary
Preact bundling changelog
.changeset/clerk-js-coinbase-preact-patch.md
Changesets entry declares a patch release for @clerk/clerk-js noting that the Coinbase Wallet web3 chunk's bundled preact version was updated to 10.27.3.
Root package dependency and constraint updates
package.json
Root devDependencies bumps @vitest/coverage-v8 and vitest from 3.2.4 to 3.2.6. pnpm.overrides is extended with version constraints for @babel/plugin-transform-modules-systemjs, axios, fast-uri, flatted, follow-redirects, ip-address, jws, minimatch, picomatch, preact, semver, smol-toml, socket.io-parser, svgo, and tmp.
Workspace package dev dependency updates
packages/headless/package.json, packages/react-router/package.json
happy-dom bumped from ^18.0.1 to ^20.8.9 and vitest bumped from 4.1.4 to 4.1.6 in headless. react-router bumped from 7.14.2 to 7.15.0 in react-router.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested labels

clerk-js

Suggested reviewers

  • dstaley
  • wobsoriano

Poem

🐰 Preact hops to ten-point-three,
vitest patches flow so free,
Dependencies align with care,
Happy-dom climbs high in air,
React-router takes the lead—updates complete!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and specifically describes the main change: patching vulnerable transitive dependencies flagged by Dependabot.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Jun 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8856

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8856

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8856

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8856

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8856

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8856

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8856

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8856

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8856

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8856

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8856

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8856

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8856

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8856

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8856

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8856

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8856

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8856

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8856

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8856

commit: c30dcc9

@github-actions

github-actionsBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-14T02:05:52.536Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on c30dcc9.

@jacekradko
jacekradko merged commit cc83980 into mainJun 16, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/dependabot-transitive-overrides branch June 16, 2026 13:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(repo): patch vulnerable transitive dependencies flagged by Dependabot by jacekradko · Pull Request #8856 · clerk/javascript · GitHub
Skip to content

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot - #8856

Merged
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides
Jun 16, 2026
Merged

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot#8856
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Most of the open Dependabot alerts on this repo trace to dev tooling, build toolchains, or lazily-loaded web3 wallet transitives that never reach customer runtime. This clears the ones worth clearing with range-scoped pnpm.overrides plus a few dev-tooling bumps.

The only change that touches a published artifact is preact 10.27.2 → 10.27.3 inside clerk-js's lazily-loaded Coinbase wallet chunk, which is why the clerk-js patch changeset is here. The happy-dom 18 → 20 bump in @clerk/headless is the other thing worth a glance; its tests stay green (403 passing).

esbuild and webpack are deliberately left out: esbuild's patch is still inside the 3-day release-age window, and a webpack bump drags its entire @webassemblyjs tree for a low-severity, build-only advisory. Both can ride the normal Renovate flow. Lockfile was regenerated with pnpm dedupe.

Summary by CodeRabbit

  • Chores
    • Updated development dependencies including test framework (vitest), coverage tools, and test environment (happy-dom)
    • Upgraded react-router to the latest available version
    • Updated preact bundled version for Coinbase Wallet integration support
    • Expanded pnpm dependency version overrides and constraints across multiple packages

…abot
Range-scoped pnpm.overrides for transitive advisories that don't reach
customer runtime (axios, jws, tmp, minimatch, picomatch, svgo, fast-uri,
ip-address, flatted, follow-redirects, smol-toml, socket.io-parser,
@babel/plugin-transform-modules-systemjs), the one shipped fix (preact
10.27.3 in clerk-js's lazy Coinbase wallet chunk), and dev-tooling bumps
(vitest 3.2.6/4.1.6, happy-dom 20, react-router 7.15.0).
@changeset-bot

changeset-botBot commented Jun 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c30dcc9

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 14, 2026 2:05am
swingsetReadyReadyPreview, CommentJun 14, 2026 2:05am

Request Review

@coderabbitai

coderabbitaiBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: b4222c80-c982-4c21-9606-9dda68ccc17f

📥 Commits

Reviewing files that changed from the base of the PR and between d46f262 and ff82a6a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .changeset/clerk-js-coinbase-preact-patch.md
  • package.json
  • packages/headless/package.json
  • packages/react-router/package.json

📝 Walkthrough

Walkthrough

This PR updates dependency versions and pnpm override constraints across the Clerk JavaScript monorepo. A patch release for @clerk/clerk-js documents the preact version bundled in the Coinbase Wallet web3 chunk being updated to 10.27.3. Root dev dependencies and workspace-enforced version constraints are bumped, and individual workspace packages receive targeted dev dependency updates.

Changes

Dependency and version constraint updates

Layer / File(s)Summary
Preact bundling changelog
.changeset/clerk-js-coinbase-preact-patch.md
Changesets entry declares a patch release for @clerk/clerk-js noting that the Coinbase Wallet web3 chunk's bundled preact version was updated to 10.27.3.
Root package dependency and constraint updates
package.json
Root devDependencies bumps @vitest/coverage-v8 and vitest from 3.2.4 to 3.2.6. pnpm.overrides is extended with version constraints for @babel/plugin-transform-modules-systemjs, axios, fast-uri, flatted, follow-redirects, ip-address, jws, minimatch, picomatch, preact, semver, smol-toml, socket.io-parser, svgo, and tmp.
Workspace package dev dependency updates
packages/headless/package.json, packages/react-router/package.json
happy-dom bumped from ^18.0.1 to ^20.8.9 and vitest bumped from 4.1.4 to 4.1.6 in headless. react-router bumped from 7.14.2 to 7.15.0 in react-router.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested labels

clerk-js

Suggested reviewers

  • dstaley
  • wobsoriano

Poem

🐰 Preact hops to ten-point-three,
vitest patches flow so free,
Dependencies align with care,
Happy-dom climbs high in air,
React-router takes the lead—updates complete!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and specifically describes the main change: patching vulnerable transitive dependencies flagged by Dependabot.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Jun 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8856

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8856

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8856

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8856

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8856

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8856

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8856

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8856

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8856

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8856

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8856

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8856

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8856

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8856

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8856

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8856

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8856

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8856

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8856

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8856

commit: c30dcc9

@github-actions

github-actionsBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-14T02:05:52.536Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on c30dcc9.

@jacekradko
jacekradko merged commit cc83980 into mainJun 16, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/dependabot-transitive-overrides branch June 16, 2026 13:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' fix(repo): patch vulnerable transitive dependencies flagged by Dependabot by jacekradko · Pull Request #8856 · clerk/javascript · GitHub
Skip to content

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot - #8856

Merged
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides
Jun 16, 2026
Merged

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot#8856
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Most of the open Dependabot alerts on this repo trace to dev tooling, build toolchains, or lazily-loaded web3 wallet transitives that never reach customer runtime. This clears the ones worth clearing with range-scoped pnpm.overrides plus a few dev-tooling bumps.

The only change that touches a published artifact is preact 10.27.2 → 10.27.3 inside clerk-js's lazily-loaded Coinbase wallet chunk, which is why the clerk-js patch changeset is here. The happy-dom 18 → 20 bump in @clerk/headless is the other thing worth a glance; its tests stay green (403 passing).

esbuild and webpack are deliberately left out: esbuild's patch is still inside the 3-day release-age window, and a webpack bump drags its entire @webassemblyjs tree for a low-severity, build-only advisory. Both can ride the normal Renovate flow. Lockfile was regenerated with pnpm dedupe.

Summary by CodeRabbit

  • Chores
    • Updated development dependencies including test framework (vitest), coverage tools, and test environment (happy-dom)
    • Upgraded react-router to the latest available version
    • Updated preact bundled version for Coinbase Wallet integration support
    • Expanded pnpm dependency version overrides and constraints across multiple packages

…abot
Range-scoped pnpm.overrides for transitive advisories that don't reach
customer runtime (axios, jws, tmp, minimatch, picomatch, svgo, fast-uri,
ip-address, flatted, follow-redirects, smol-toml, socket.io-parser,
@babel/plugin-transform-modules-systemjs), the one shipped fix (preact
10.27.3 in clerk-js's lazy Coinbase wallet chunk), and dev-tooling bumps
(vitest 3.2.6/4.1.6, happy-dom 20, react-router 7.15.0).
@changeset-bot

changeset-botBot commented Jun 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c30dcc9

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 14, 2026 2:05am
swingsetReadyReadyPreview, CommentJun 14, 2026 2:05am

Request Review

@coderabbitai

coderabbitaiBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: b4222c80-c982-4c21-9606-9dda68ccc17f

📥 Commits

Reviewing files that changed from the base of the PR and between d46f262 and ff82a6a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .changeset/clerk-js-coinbase-preact-patch.md
  • package.json
  • packages/headless/package.json
  • packages/react-router/package.json

📝 Walkthrough

Walkthrough

This PR updates dependency versions and pnpm override constraints across the Clerk JavaScript monorepo. A patch release for @clerk/clerk-js documents the preact version bundled in the Coinbase Wallet web3 chunk being updated to 10.27.3. Root dev dependencies and workspace-enforced version constraints are bumped, and individual workspace packages receive targeted dev dependency updates.

Changes

Dependency and version constraint updates

Layer / File(s)Summary
Preact bundling changelog
.changeset/clerk-js-coinbase-preact-patch.md
Changesets entry declares a patch release for @clerk/clerk-js noting that the Coinbase Wallet web3 chunk's bundled preact version was updated to 10.27.3.
Root package dependency and constraint updates
package.json
Root devDependencies bumps @vitest/coverage-v8 and vitest from 3.2.4 to 3.2.6. pnpm.overrides is extended with version constraints for @babel/plugin-transform-modules-systemjs, axios, fast-uri, flatted, follow-redirects, ip-address, jws, minimatch, picomatch, preact, semver, smol-toml, socket.io-parser, svgo, and tmp.
Workspace package dev dependency updates
packages/headless/package.json, packages/react-router/package.json
happy-dom bumped from ^18.0.1 to ^20.8.9 and vitest bumped from 4.1.4 to 4.1.6 in headless. react-router bumped from 7.14.2 to 7.15.0 in react-router.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested labels

clerk-js

Suggested reviewers

  • dstaley
  • wobsoriano

Poem

🐰 Preact hops to ten-point-three,
vitest patches flow so free,
Dependencies align with care,
Happy-dom climbs high in air,
React-router takes the lead—updates complete!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and specifically describes the main change: patching vulnerable transitive dependencies flagged by Dependabot.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Jun 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8856

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8856

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8856

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8856

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8856

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8856

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8856

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8856

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8856

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8856

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8856

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8856

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8856

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8856

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8856

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8856

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8856

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8856

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8856

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8856

commit: c30dcc9

@github-actions

github-actionsBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-14T02:05:52.536Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on c30dcc9.

@jacekradko
jacekradko merged commit cc83980 into mainJun 16, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/dependabot-transitive-overrides branch June 16, 2026 13:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(repo): patch vulnerable transitive dependencies flagged by Dependabot by jacekradko · Pull Request #8856 · clerk/javascript · GitHub
Skip to content

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot - #8856

Merged
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides
Jun 16, 2026
Merged

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot#8856
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Most of the open Dependabot alerts on this repo trace to dev tooling, build toolchains, or lazily-loaded web3 wallet transitives that never reach customer runtime. This clears the ones worth clearing with range-scoped pnpm.overrides plus a few dev-tooling bumps.

The only change that touches a published artifact is preact 10.27.2 → 10.27.3 inside clerk-js's lazily-loaded Coinbase wallet chunk, which is why the clerk-js patch changeset is here. The happy-dom 18 → 20 bump in @clerk/headless is the other thing worth a glance; its tests stay green (403 passing).

esbuild and webpack are deliberately left out: esbuild's patch is still inside the 3-day release-age window, and a webpack bump drags its entire @webassemblyjs tree for a low-severity, build-only advisory. Both can ride the normal Renovate flow. Lockfile was regenerated with pnpm dedupe.

Summary by CodeRabbit

  • Chores
    • Updated development dependencies including test framework (vitest), coverage tools, and test environment (happy-dom)
    • Upgraded react-router to the latest available version
    • Updated preact bundled version for Coinbase Wallet integration support
    • Expanded pnpm dependency version overrides and constraints across multiple packages

…abot
Range-scoped pnpm.overrides for transitive advisories that don't reach
customer runtime (axios, jws, tmp, minimatch, picomatch, svgo, fast-uri,
ip-address, flatted, follow-redirects, smol-toml, socket.io-parser,
@babel/plugin-transform-modules-systemjs), the one shipped fix (preact
10.27.3 in clerk-js's lazy Coinbase wallet chunk), and dev-tooling bumps
(vitest 3.2.6/4.1.6, happy-dom 20, react-router 7.15.0).
@changeset-bot

changeset-botBot commented Jun 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c30dcc9

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 14, 2026 2:05am
swingsetReadyReadyPreview, CommentJun 14, 2026 2:05am

Request Review

@coderabbitai

coderabbitaiBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: b4222c80-c982-4c21-9606-9dda68ccc17f

📥 Commits

Reviewing files that changed from the base of the PR and between d46f262 and ff82a6a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .changeset/clerk-js-coinbase-preact-patch.md
  • package.json
  • packages/headless/package.json
  • packages/react-router/package.json

📝 Walkthrough

Walkthrough

This PR updates dependency versions and pnpm override constraints across the Clerk JavaScript monorepo. A patch release for @clerk/clerk-js documents the preact version bundled in the Coinbase Wallet web3 chunk being updated to 10.27.3. Root dev dependencies and workspace-enforced version constraints are bumped, and individual workspace packages receive targeted dev dependency updates.

Changes

Dependency and version constraint updates

Layer / File(s)Summary
Preact bundling changelog
.changeset/clerk-js-coinbase-preact-patch.md
Changesets entry declares a patch release for @clerk/clerk-js noting that the Coinbase Wallet web3 chunk's bundled preact version was updated to 10.27.3.
Root package dependency and constraint updates
package.json
Root devDependencies bumps @vitest/coverage-v8 and vitest from 3.2.4 to 3.2.6. pnpm.overrides is extended with version constraints for @babel/plugin-transform-modules-systemjs, axios, fast-uri, flatted, follow-redirects, ip-address, jws, minimatch, picomatch, preact, semver, smol-toml, socket.io-parser, svgo, and tmp.
Workspace package dev dependency updates
packages/headless/package.json, packages/react-router/package.json
happy-dom bumped from ^18.0.1 to ^20.8.9 and vitest bumped from 4.1.4 to 4.1.6 in headless. react-router bumped from 7.14.2 to 7.15.0 in react-router.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested labels

clerk-js

Suggested reviewers

  • dstaley
  • wobsoriano

Poem

🐰 Preact hops to ten-point-three,
vitest patches flow so free,
Dependencies align with care,
Happy-dom climbs high in air,
React-router takes the lead—updates complete!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and specifically describes the main change: patching vulnerable transitive dependencies flagged by Dependabot.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Jun 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8856

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8856

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8856

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8856

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8856

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8856

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8856

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8856

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8856

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8856

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8856

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8856

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8856

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8856

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8856

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8856

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8856

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8856

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8856

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8856

commit: c30dcc9

@github-actions

github-actionsBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-14T02:05:52.536Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on c30dcc9.

@jacekradko
jacekradko merged commit cc83980 into mainJun 16, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/dependabot-transitive-overrides branch June 16, 2026 13:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' fix(repo): patch vulnerable transitive dependencies flagged by Dependabot by jacekradko · Pull Request #8856 · clerk/javascript · GitHub
Skip to content

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot - #8856

Merged
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides
Jun 16, 2026
Merged

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot#8856
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Most of the open Dependabot alerts on this repo trace to dev tooling, build toolchains, or lazily-loaded web3 wallet transitives that never reach customer runtime. This clears the ones worth clearing with range-scoped pnpm.overrides plus a few dev-tooling bumps.

The only change that touches a published artifact is preact 10.27.2 → 10.27.3 inside clerk-js's lazily-loaded Coinbase wallet chunk, which is why the clerk-js patch changeset is here. The happy-dom 18 → 20 bump in @clerk/headless is the other thing worth a glance; its tests stay green (403 passing).

esbuild and webpack are deliberately left out: esbuild's patch is still inside the 3-day release-age window, and a webpack bump drags its entire @webassemblyjs tree for a low-severity, build-only advisory. Both can ride the normal Renovate flow. Lockfile was regenerated with pnpm dedupe.

Summary by CodeRabbit

  • Chores
    • Updated development dependencies including test framework (vitest), coverage tools, and test environment (happy-dom)
    • Upgraded react-router to the latest available version
    • Updated preact bundled version for Coinbase Wallet integration support
    • Expanded pnpm dependency version overrides and constraints across multiple packages

…abot
Range-scoped pnpm.overrides for transitive advisories that don't reach
customer runtime (axios, jws, tmp, minimatch, picomatch, svgo, fast-uri,
ip-address, flatted, follow-redirects, smol-toml, socket.io-parser,
@babel/plugin-transform-modules-systemjs), the one shipped fix (preact
10.27.3 in clerk-js's lazy Coinbase wallet chunk), and dev-tooling bumps
(vitest 3.2.6/4.1.6, happy-dom 20, react-router 7.15.0).
@changeset-bot

changeset-botBot commented Jun 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c30dcc9

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 14, 2026 2:05am
swingsetReadyReadyPreview, CommentJun 14, 2026 2:05am

Request Review

@coderabbitai

coderabbitaiBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: b4222c80-c982-4c21-9606-9dda68ccc17f

📥 Commits

Reviewing files that changed from the base of the PR and between d46f262 and ff82a6a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .changeset/clerk-js-coinbase-preact-patch.md
  • package.json
  • packages/headless/package.json
  • packages/react-router/package.json

📝 Walkthrough

Walkthrough

This PR updates dependency versions and pnpm override constraints across the Clerk JavaScript monorepo. A patch release for @clerk/clerk-js documents the preact version bundled in the Coinbase Wallet web3 chunk being updated to 10.27.3. Root dev dependencies and workspace-enforced version constraints are bumped, and individual workspace packages receive targeted dev dependency updates.

Changes

Dependency and version constraint updates

Layer / File(s)Summary
Preact bundling changelog
.changeset/clerk-js-coinbase-preact-patch.md
Changesets entry declares a patch release for @clerk/clerk-js noting that the Coinbase Wallet web3 chunk's bundled preact version was updated to 10.27.3.
Root package dependency and constraint updates
package.json
Root devDependencies bumps @vitest/coverage-v8 and vitest from 3.2.4 to 3.2.6. pnpm.overrides is extended with version constraints for @babel/plugin-transform-modules-systemjs, axios, fast-uri, flatted, follow-redirects, ip-address, jws, minimatch, picomatch, preact, semver, smol-toml, socket.io-parser, svgo, and tmp.
Workspace package dev dependency updates
packages/headless/package.json, packages/react-router/package.json
happy-dom bumped from ^18.0.1 to ^20.8.9 and vitest bumped from 4.1.4 to 4.1.6 in headless. react-router bumped from 7.14.2 to 7.15.0 in react-router.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested labels

clerk-js

Suggested reviewers

  • dstaley
  • wobsoriano

Poem

🐰 Preact hops to ten-point-three,
vitest patches flow so free,
Dependencies align with care,
Happy-dom climbs high in air,
React-router takes the lead—updates complete!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and specifically describes the main change: patching vulnerable transitive dependencies flagged by Dependabot.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Jun 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8856

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8856

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8856

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8856

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8856

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8856

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8856

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8856

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8856

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8856

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8856

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8856

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8856

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8856

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8856

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8856

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8856

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8856

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8856

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8856

commit: c30dcc9

@github-actions

github-actionsBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-14T02:05:52.536Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on c30dcc9.

@jacekradko
jacekradko merged commit cc83980 into mainJun 16, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/dependabot-transitive-overrides branch June 16, 2026 13:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); fix(repo): patch vulnerable transitive dependencies flagged by Dependabot by jacekradko · Pull Request #8856 · clerk/javascript · GitHub
Skip to content

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot - #8856

Merged
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides
Jun 16, 2026
Merged

fix(repo): patch vulnerable transitive dependencies flagged by Dependabot#8856
jacekradko merged 2 commits into
mainfrom
jacek/dependabot-transitive-overrides

Conversation

@jacekradko

@jacekradkojacekradko commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Most of the open Dependabot alerts on this repo trace to dev tooling, build toolchains, or lazily-loaded web3 wallet transitives that never reach customer runtime. This clears the ones worth clearing with range-scoped pnpm.overrides plus a few dev-tooling bumps.

The only change that touches a published artifact is preact 10.27.2 → 10.27.3 inside clerk-js's lazily-loaded Coinbase wallet chunk, which is why the clerk-js patch changeset is here. The happy-dom 18 → 20 bump in @clerk/headless is the other thing worth a glance; its tests stay green (403 passing).

esbuild and webpack are deliberately left out: esbuild's patch is still inside the 3-day release-age window, and a webpack bump drags its entire @webassemblyjs tree for a low-severity, build-only advisory. Both can ride the normal Renovate flow. Lockfile was regenerated with pnpm dedupe.

Summary by CodeRabbit

  • Chores
    • Updated development dependencies including test framework (vitest), coverage tools, and test environment (happy-dom)
    • Upgraded react-router to the latest available version
    • Updated preact bundled version for Coinbase Wallet integration support
    • Expanded pnpm dependency version overrides and constraints across multiple packages

…abot
Range-scoped pnpm.overrides for transitive advisories that don't reach
customer runtime (axios, jws, tmp, minimatch, picomatch, svgo, fast-uri,
ip-address, flatted, follow-redirects, smol-toml, socket.io-parser,
@babel/plugin-transform-modules-systemjs), the one shipped fix (preact
10.27.3 in clerk-js's lazy Coinbase wallet chunk), and dev-tooling bumps
(vitest 3.2.6/4.1.6, happy-dom 20, react-router 7.15.0).
@changeset-bot

changeset-botBot commented Jun 13, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c30dcc9

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
NameType
@clerk/clerk-jsPatch
@clerk/chrome-extensionPatch
@clerk/expoPatch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercelBot commented Jun 13, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreview, CommentJun 14, 2026 2:05am
swingsetReadyReadyPreview, CommentJun 14, 2026 2:05am

Request Review

@coderabbitai

coderabbitaiBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Repository UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: b4222c80-c982-4c21-9606-9dda68ccc17f

📥 Commits

Reviewing files that changed from the base of the PR and between d46f262 and ff82a6a.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (4)
  • .changeset/clerk-js-coinbase-preact-patch.md
  • package.json
  • packages/headless/package.json
  • packages/react-router/package.json

📝 Walkthrough

Walkthrough

This PR updates dependency versions and pnpm override constraints across the Clerk JavaScript monorepo. A patch release for @clerk/clerk-js documents the preact version bundled in the Coinbase Wallet web3 chunk being updated to 10.27.3. Root dev dependencies and workspace-enforced version constraints are bumped, and individual workspace packages receive targeted dev dependency updates.

Changes

Dependency and version constraint updates

Layer / File(s)Summary
Preact bundling changelog
.changeset/clerk-js-coinbase-preact-patch.md
Changesets entry declares a patch release for @clerk/clerk-js noting that the Coinbase Wallet web3 chunk's bundled preact version was updated to 10.27.3.
Root package dependency and constraint updates
package.json
Root devDependencies bumps @vitest/coverage-v8 and vitest from 3.2.4 to 3.2.6. pnpm.overrides is extended with version constraints for @babel/plugin-transform-modules-systemjs, axios, fast-uri, flatted, follow-redirects, ip-address, jws, minimatch, picomatch, preact, semver, smol-toml, socket.io-parser, svgo, and tmp.
Workspace package dev dependency updates
packages/headless/package.json, packages/react-router/package.json
happy-dom bumped from ^18.0.1 to ^20.8.9 and vitest bumped from 4.1.4 to 4.1.6 in headless. react-router bumped from 7.14.2 to 7.15.0 in react-router.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~8 minutes

Suggested labels

clerk-js

Suggested reviewers

  • dstaley
  • wobsoriano

Poem

🐰 Preact hops to ten-point-three,
vitest patches flow so free,
Dependencies align with care,
Happy-dom climbs high in air,
React-router takes the lead—updates complete!

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check nameStatusExplanation
Description Check✅ PassedCheck skipped - CodeRabbit’s high-level summary is enabled.
Title check✅ PassedThe title clearly and specifically describes the main change: patching vulnerable transitive dependencies flagged by Dependabot.
Docstring Coverage✅ PassedNo functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check✅ PassedCheck skipped because no linked issues were found for this pull request.
Out of Scope Changes check✅ PassedCheck skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-newBot commented Jun 13, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8856

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8856

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8856

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8856

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8856

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8856

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8856

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8856

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8856

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8856

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8856

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8856

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8856

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8856

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8856

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8856

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8856

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8856

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8856

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8856

commit: c30dcc9

@github-actions

github-actionsBot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-14T02:05:52.536Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on c30dcc9.

@jacekradko
jacekradko merged commit cc83980 into mainJun 16, 2026
47 checks passed
@jacekradko
jacekradko deleted the jacek/dependabot-transitive-overrides branch June 16, 2026 13:39
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@jacekradko@wobsoriano