Skip to content

ci(repo): Version packages - #9306

Merged
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main
Aug 4, 2026
Merged

ci(repo): Version packages#9306
thiskevinwang merged 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookie clerk-cookie commented Jul 31, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/clerk-js@6.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Recover from partitioned-cookie startup races by removing stale non-partitioned cookies when partitioned cookies become available. (#9286) by @thiskevinwang

  • Complete the Safari ITP cookie refresh when setActive({ redirectUrl }) navigates. (#9308) by @dmoerner

    Safari's ITP caps the client cookie at 7 days when it is re-issued from a fetch, so setActive() routes its redirect through /v1/client/touch to restore the full lifetime. That navigation was immediately followed by a second one to the undecorated redirect URL, which superseded it and aborted the touch request before it completed, leaving the cookie capped.

    This applies to flows that pass redirectUrl without a navigate callback — email link sign-in, the password reset success screen, the OAuth popup flow, and direct setActive({ session, redirectUrl }) calls — in apps where Clerk performs a full page navigation rather than handing off to a router. Users still landed on the correct page, so the only symptom was Safari sessions ending after 7 days and returning devices being challenged as if they were new.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/localizations@4.14.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/shared@4.26.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

@clerk/ui@1.28.0

Minor Changes

  • Support sign-in-or-sign-up combined flow with Clerk component (#7928) by @dmoerner

    when strict enumeration protection is enabled.

    On development instances, <SignIn> now logs a warning when the sign-in-or-up flow is rendered on an
    instance that has both password and strict enumeration protection enabled. In that configuration
    visitors without an account are routed to the password screen and cannot complete a sign-up, so the
    warning names both settings and how to resolve them.

Patch Changes

  • fix(ui): Avoid races between email link tabs when using sign up if missing (#9328) by @dmoerner

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0
    • @clerk/localizations@4.14.0

@clerk/astro@4.0.6

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/backend@3.15.1

Patch Changes

  • Add the optional emailAddressIdentificationStatus and phoneNumberIdentificationStatus parameters to CreateUserParams. The Backend API has supported these arrays on POST /v1/users since they shipped, but createUser() had no way to pass them, so every email address and phone number was necessarily created verified. Each array runs parallel to emailAddress / phoneNumber — one item per identifier, applied by position — and an item set to 'reserved' creates that identifier unverified but still usable for sign-in and locked so no other user can claim it. (#9305) by @dmoerner

    The createUser() documentation is corrected accordingly: it stated unconditionally that created email addresses and phone numbers are automatically verified, which is only the default.

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/chrome-extension@3.1.65

Patch Changes

@clerk/electron@0.0.26

Patch Changes

@clerk/expo@4.2.1

Patch Changes

@clerk/expo-passkeys@2.0.5

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/express@2.1.50

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/fastify@3.1.60

Patch Changes

  • Respond with 400 Bad Request instead of surfacing a 500 when an incoming request cannot be represented as a fetch Request. Vulnerability-scanner probes such as hostless // request targets, targets that parse as credentialed URLs, and forbidden methods like TRACE previously threw inside the middleware and polluted error logs. (#9290) by @wobsoriano

  • Updated dependencies [a601cd7, 5c81479]:

    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/hono@0.1.60

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/nextjs@7.6.5

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/nuxt@3.0.2

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0
    • @clerk/vue@2.4.23

@clerk/react@6.12.11

Patch Changes

  • Allow ClerkProvider to omit publishableKey when it is supplied through VITE_CLERK_PUBLISHABLE_KEY or CLERK_PUBLISHABLE_KEY. (#9314) by @SarahSoutoul

  • Updated dependencies [5c81479]:

    • @clerk/shared@4.26.0

@clerk/react-router@3.6.4

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/tanstack-react-start@1.4.27

Patch Changes

  • Updated dependencies [a601cd7, bbe51ff, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/react@6.12.11
    • @clerk/shared@4.26.0

@clerk/testing@2.2.17

Patch Changes

  • Updated dependencies [a601cd7, 5c81479]:
    • @clerk/backend@3.15.1
    • @clerk/shared@4.26.0

@clerk/vue@2.4.23

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/headless@0.0.19

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/msw@0.0.55

Patch Changes

  • Updated dependencies [5c81479]:
    • @clerk/shared@4.26.0

@clerk/swingset@0.0.29

Patch Changes

  • Updated dependencies [5c81479, 83a8fc5]:
    • @clerk/ui@1.28.0
    • @clerk/headless@0.0.19

@vercel

vercel Bot commented Jul 31, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
clerk-js-sandbox Ready Ready Preview Aug 4, 2026 4:26pm
swingset Ready Ready Preview Aug 4, 2026 4:26pm

Request Review

@pkg-pr-new

pkg-pr-new Bot commented Jul 31, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9306

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9306

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9306

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9306

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9306

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9306

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9306

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9306

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9306

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9306

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9306

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9306

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9306

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9306

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9306

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9306

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9306

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9306

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9306

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9306

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9306

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9306

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9306

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9306

commit: 792abc3

@github-actions

github-actions Bot commented Jul 31, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-08-04T16:30:00.992Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 0
🔴 Breaking changes 0
🟡 Non-breaking changes 0
🟢 Additions 0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 792abc3.

@clerk-cookie
clerk-cookie force-pushed the changeset-release/main branch from 2f2e1f0 to 54d1eb6 Compare August 3, 2026 17:08
@clerk-cookie
clerk-cookie force-pushed the changeset-release/main branch from 54d1eb6 to 68eea6c Compare August 3, 2026 17:36
@clerk-cookie
clerk-cookie force-pushed the changeset-release/main branch from 68eea6c to e099c4e Compare August 3, 2026 18:43
@clerk-cookie
clerk-cookie force-pushed the changeset-release/main branch from e099c4e to efdb432 Compare August 4, 2026 07:01
@github-actions github-actions Bot added the react label Aug 4, 2026
@clerk-cookie
clerk-cookie force-pushed the changeset-release/main branch from efdb432 to 44034b0 Compare August 4, 2026 13:18
@thiskevinwang
thiskevinwang merged commit 438f2e5 into main Aug 4, 2026
61 of 68 checks passed
@thiskevinwang
thiskevinwang deleted the changeset-release/main branch August 4, 2026 16:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants