Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookieclerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewAug 4, 2026 4:26pm
swingsetReadyReadyPreviewAug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actionsBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6CompareAugust 3, 2026 17:08
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 54d1eb6 to 68eea6cCompareAugust 3, 2026 17:36
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 68eea6c to e099c4eCompareAugust 3, 2026 18:43
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from e099c4e to efdb432CompareAugust 4, 2026 07:01
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from efdb432 to 44034b0CompareAugust 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into mainAug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@clerk-cookie@dstaley@thiskevinwang@brkalow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
ci(repo): Version packages by clerk-cookie · Pull Request #9306 · clerk/javascript · GitHub
Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookieclerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewAug 4, 2026 4:26pm
swingsetReadyReadyPreviewAug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actionsBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6CompareAugust 3, 2026 17:08
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 54d1eb6 to 68eea6cCompareAugust 3, 2026 17:36
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 68eea6c to e099c4eCompareAugust 3, 2026 18:43
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from e099c4e to efdb432CompareAugust 4, 2026 07:01
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from efdb432 to 44034b0CompareAugust 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into mainAug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@clerk-cookie@dstaley@thiskevinwang@brkalow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(repo): Version packages by clerk-cookie · Pull Request #9306 · clerk/javascript · GitHub
Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookieclerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewAug 4, 2026 4:26pm
swingsetReadyReadyPreviewAug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actionsBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6CompareAugust 3, 2026 17:08
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 54d1eb6 to 68eea6cCompareAugust 3, 2026 17:36
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 68eea6c to e099c4eCompareAugust 3, 2026 18:43
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from e099c4e to efdb432CompareAugust 4, 2026 07:01
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from efdb432 to 44034b0CompareAugust 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into mainAug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@clerk-cookie@dstaley@thiskevinwang@brkalow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(repo): Version packages by clerk-cookie · Pull Request #9306 · clerk/javascript · GitHub
Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookieclerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewAug 4, 2026 4:26pm
swingsetReadyReadyPreviewAug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actionsBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6CompareAugust 3, 2026 17:08
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 54d1eb6 to 68eea6cCompareAugust 3, 2026 17:36
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 68eea6c to e099c4eCompareAugust 3, 2026 18:43
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from e099c4e to efdb432CompareAugust 4, 2026 07:01
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from efdb432 to 44034b0CompareAugust 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into mainAug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@clerk-cookie@dstaley@thiskevinwang@brkalow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' ci(repo): Version packages by clerk-cookie · Pull Request #9306 · clerk/javascript · GitHub
Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookieclerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewAug 4, 2026 4:26pm
swingsetReadyReadyPreviewAug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actionsBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6CompareAugust 3, 2026 17:08
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 54d1eb6 to 68eea6cCompareAugust 3, 2026 17:36
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 68eea6c to e099c4eCompareAugust 3, 2026 18:43
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from e099c4e to efdb432CompareAugust 4, 2026 07:01
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from efdb432 to 44034b0CompareAugust 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into mainAug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@clerk-cookie@dstaley@thiskevinwang@brkalow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(repo): Version packages by clerk-cookie · Pull Request #9306 · clerk/javascript · GitHub
Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookieclerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewAug 4, 2026 4:26pm
swingsetReadyReadyPreviewAug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actionsBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6CompareAugust 3, 2026 17:08
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 54d1eb6 to 68eea6cCompareAugust 3, 2026 17:36
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 68eea6c to e099c4eCompareAugust 3, 2026 18:43
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from e099c4e to efdb432CompareAugust 4, 2026 07:01
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from efdb432 to 44034b0CompareAugust 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into mainAug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@clerk-cookie@dstaley@thiskevinwang@brkalow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' ci(repo): Version packages by clerk-cookie · Pull Request #9306 · clerk/javascript · GitHub
Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookieclerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewAug 4, 2026 4:26pm
swingsetReadyReadyPreviewAug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actionsBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6CompareAugust 3, 2026 17:08
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 54d1eb6 to 68eea6cCompareAugust 3, 2026 17:36
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 68eea6c to e099c4eCompareAugust 3, 2026 18:43
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from e099c4e to efdb432CompareAugust 4, 2026 07:01
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from efdb432 to 44034b0CompareAugust 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into mainAug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@clerk-cookie@dstaley@thiskevinwang@brkalow
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); ci(repo): Version packages by clerk-cookie · Pull Request #9306 · clerk/javascript · GitHub
Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookieclerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercelBot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

ProjectDeploymentActionsUpdated (UTC)
clerk-js-sandboxReadyReadyPreviewAug 4, 2026 4:26pm
swingsetReadyReadyPreviewAug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-newBot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actionsBot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

MetricCount
Packages analyzed19
Packages with changes0
🔴 Breaking changes0
🟡 Non-breaking changes0
🟢 Additions0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6CompareAugust 3, 2026 17:08
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 54d1eb6 to 68eea6cCompareAugust 3, 2026 17:36
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from 68eea6c to e099c4eCompareAugust 3, 2026 18:43
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from e099c4e to efdb432CompareAugust 4, 2026 07:01
@clerk-cookie
clerk-cookieforce-pushed the changeset-release/main branch from efdb432 to 44034b0CompareAugust 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into mainAug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@clerk-cookie@dstaley@thiskevinwang@brkalow