Skip to content

ci(repo): Version packages - #9262

Open
clerk-cookie wants to merge 1 commit into
mainfrom
changeset-release/main
Open

ci(repo): Version packages#9262
clerk-cookie wants to merge 1 commit into
mainfrom
changeset-release/main

Conversation

@clerk-cookie

@clerk-cookie clerk-cookie commented Jul 27, 2026

Copy link
Copy Markdown
Collaborator

This PR was opened by the Changesets release GitHub action. When you're ready to do a release, you can merge this and the packages will be published to npm automatically. If you're not ready to do a release yet, that's fine, whenever you add more changesets to main, this PR will be updated.

Releases

@clerk/[email protected]

Major Changes

  • Drop support for Nuxt 3, which reaches end-of-life on July 31, 2026. @clerk/nuxt now requires Nuxt 4, and the minimum supported Node.js version is now ^20.19.0 || >=22.12.0 to match Nuxt 4's own requirement. If you are still on Nuxt 3, follow the Nuxt upgrade guide to upgrade your project before updating @clerk/nuxt. (#9258) by @wobsoriano

  • Remove createRouteMatcher from @clerk/nuxt/server and the auto-imported client-side createRouteMatcher. Middleware-based auth checks rely on path matching, which can diverge from how requests are actually routed and leave protected resources reachable. Move auth checks into the resources themselves. (#9258) by @wobsoriano

    Protect API routes inside the event handler itself:

    export default defineEventHandler(event => {
      const { userId } = event.context.auth();
    
      if (!userId) {
        throw createError({ statusCode: 401, statusMessage: 'Unauthorized' });
      }
    
      return { userId };
    });

    Protect pages with a named route middleware and opt pages into it with definePageMeta(). Child routes inherit the middleware applied to their parent, so a single declaration can protect a whole section:

    // app/middleware/auth.ts
    export default defineNuxtRouteMiddleware(() => {
      const { isSignedIn } = useAuth();
    
      if (!isSignedIn.value) {
        return navigateTo('/sign-in');
      }
    });
    <script setup>
    definePageMeta({ middleware: 'auth' });
    </script>

    If you want to hand this work to a coding agent, use this migration prompt:

    Migrate my Nuxt project away from Clerk's removed `createRouteMatcher` API.
    
    1. Find every matcher created with `createRouteMatcher`, along with the logic
       that uses it (throwing 401 errors, calling `navigateTo('/sign-in')`, etc.).
       Matchers can appear in Nitro server middleware (imported from
       `@clerk/nuxt/server`) or in Nuxt route middleware (auto-imported).
    2. For every API route those matchers protected, move the auth check into the
       event handler itself:
       const { userId } = event.context.auth();
       if (!userId) throw createError({ statusCode: 401, statusMessage: 'Unauthorized' });
       Keep any role or permission checks (`event.context.auth().has(...)`) with
       the resource as well.
    3. For every page those matchers protected, create a named route middleware in
       `app/middleware/` that checks `useAuth()` and redirects with `navigateTo()`,
       then opt pages into it with `definePageMeta({ middleware: 'auth' })`. Child
       routes inherit the middleware applied to their parent.
    4. Remove the `createRouteMatcher` imports and calls. Keep `clerkMiddleware()`
       itself. Middleware logic unrelated to auth protection (headers, locale
       redirects, etc.) may stay, using plain `getRequestURL(event).pathname`
       checks. Plain pathname checks do not normalize percent-encoding
       (`/api/%61dmin` will not match a check for `/api/admin`), so never use
       them for auth or security decisions. Those belong on the resource itself,
       as in steps 2 and 3.
    5. Make sure every route previously covered by a matcher pattern (including
       glob patterns like `/dashboard(.*)`) now has its own check, then verify the
       project builds.

Patch Changes

@clerk/[email protected]

Minor Changes

  • Align the EnterpriseConnection response resource with what the Backend API actually returns: (#9156) by @manovotny
    • EnterpriseConnection now exposes provider, logoPublicUrl, allowOrganizationAccountLinking, authenticatable, disableJitProvisioning, and customAttributes.
    • EnterpriseConnectionSamlConnection now exposes active, forceAuthn, and loginHint.
    • EnterpriseConnectionOauthConfig now exposes providerKey, authUrl, tokenUrl, userInfoUrl, and requiresPkce.
    • Deprecated properties the Backend API never returns, which were always undefined despite their declared types: allowSubdomains on EnterpriseConnection (use samlConnection.allowSubdomains), and idpMetadata and syncUserAttributes on EnterpriseConnectionSamlConnection (use the top-level syncUserAttributes).
    • organizationId is now normalized to null when the Backend API omits it, matching its declared string | null type. Properties backed by optional API fields (for example oauthConfig.clientId and the SAML IdP fields) are now typed as possibly undefined to match runtime behavior.

Patch Changes

@clerk/[email protected]

Minor Changes

  • Add a new Mosaic Avatar compound component (StyleX). Avatar.Root owns shape (circle | square) and size (lg | md | sm | xs); compose Avatar.Image (renders once the image loads) and Avatar.Fallback (shown while the image is pending or has failed, with an optional delayMs) inside it. (#9230) by @alexcarpenter

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

  • Expose whether an organization member has been deprovisioned, and mark deprovisioned members as inactive in the Organization Profile. (#9202) by @NicolasLopes7

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@clerk/[email protected]

Patch Changes

@vercel

vercel Bot commented Jul 27, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
clerk-js-sandbox Ready Ready Preview, Comment Jul 28, 2026 7:18pm
swingset Ready Ready Preview, Comment Jul 28, 2026 7:18pm

Request Review

@pkg-pr-new

pkg-pr-new Bot commented Jul 27, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9262

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9262

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9262

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9262

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9262

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9262

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9262

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9262

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9262

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9262

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9262

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9262

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9262

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9262

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9262

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9262

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9262

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9262

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9262

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9262

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9262

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9262

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9262

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9262

commit: 600249a

@github-actions

github-actions Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-07-28T19:19:28.843Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 0
🔴 Breaking changes 0
🟡 Non-breaking changes 0
🟢 Additions 0

No API Changes Detected

All packages have stable APIs with no detected changes.


Report generated by Break Check

Last ran on 600249a.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant