Skip to content

chore: bump @clerk/react from 6.10.4 to 6.12.0#1953

Merged
sanjay-kv merged 1 commit into
mainfrom
dependabot/npm_and_yarn/clerk/react-6.12.0
Jul 9, 2026
Merged

chore: bump @clerk/react from 6.10.4 to 6.12.0#1953
sanjay-kv merged 1 commit into
mainfrom
dependabot/npm_and_yarn/clerk/react-6.12.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 8, 2026

Copy link
Copy Markdown
Contributor

Bumps @clerk/react from 6.10.4 to 6.12.0.

Release notes

Sourced from @​clerk/react's releases.

@​clerk/react@​6.12.0

Minor Changes

  • Add support for Clerk Protect mid-flow SDK challenges (protect_check) on both sign-up and sign-in. (#8329) by @​zourzouvillys

    When the Protect antifraud service issues a challenge, responses now carry a protectCheck field with { status, token, sdkUrl, expiresAt?, uiHints? }. Clients resolve the gate by loading the SDK at sdkUrl, executing the challenge, and submitting the resulting proof token via signUp.submitProtectCheck({ proofToken }) or signIn.submitProtectCheck({ proofToken }). The response may carry a chained challenge, which the SDK resolves iteratively.

    Sign-in adds a new 'needs_protect_check' value to the SignInStatus union. Upgrading this package is type-only and does not change runtime behavior: the server returns the new status (and the protectCheck field) only for instances where Protect mid-flow challenges have been explicitly enabled — the feature is off by default and is not enabled for existing instances by upgrading. The server additionally only emits the new status value to SDK versions that understand it, so older clients never receive an unknown status.

    If an exhaustive switch on signIn.status flags the new value after upgrading, handle it by running the challenge described by protectCheck and submitting the proof via submitProtectCheck(). Clients should treat the protectCheck field as the authoritative gate signal and fall back to the status value for defense in depth.

    The pre-built <SignIn /> and <SignUp /> components handle the gate automatically by routing to a new protect-check route that runs the challenge SDK and resumes the flow on completion.

Patch Changes

@​clerk/react@​6.11.4

Patch Changes

@​clerk/react@​6.11.3

Patch Changes

@​clerk/react@​6.11.1

Patch Changes

  • Updated dependencies [19ce04a]:
    • @​clerk/shared@​4.22.0
Changelog

Sourced from @​clerk/react's changelog.

6.12.0

Minor Changes

  • Add support for Clerk Protect mid-flow SDK challenges (protect_check) on both sign-up and sign-in. (#8329) by @​zourzouvillys

    When the Protect antifraud service issues a challenge, responses now carry a protectCheck field with { status, token, sdkUrl, expiresAt?, uiHints? }. Clients resolve the gate by loading the SDK at sdkUrl, executing the challenge, and submitting the resulting proof token via signUp.submitProtectCheck({ proofToken }) or signIn.submitProtectCheck({ proofToken }). The response may carry a chained challenge, which the SDK resolves iteratively.

    Sign-in adds a new 'needs_protect_check' value to the SignInStatus union. Upgrading this package is type-only and does not change runtime behavior: the server returns the new status (and the protectCheck field) only for instances where Protect mid-flow challenges have been explicitly enabled — the feature is off by default and is not enabled for existing instances by upgrading. The server additionally only emits the new status value to SDK versions that understand it, so older clients never receive an unknown status.

    If an exhaustive switch on signIn.status flags the new value after upgrading, handle it by running the challenge described by protectCheck and submitting the proof via submitProtectCheck(). Clients should treat the protectCheck field as the authoritative gate signal and fall back to the status value for defense in depth.

    The pre-built <SignIn /> and <SignUp /> components handle the gate automatically by routing to a new protect-check route that runs the challenge SDK and resumes the flow on completion.

Patch Changes

6.11.4

Patch Changes

6.11.3

Patch Changes

6.11.2

Patch Changes

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@clerk/react](https://github.com/clerk/javascript/tree/HEAD/packages/react) from 6.10.4 to 6.12.0.
- [Release notes](https://github.com/clerk/javascript/releases)
- [Changelog](https://github.com/clerk/javascript/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/clerk/javascript/commits/@clerk/react@6.12.0/packages/react)

---
updated-dependencies:
- dependency-name: "@clerk/react"
  dependency-version: 6.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Jul 8, 2026
@dependabot
dependabot Bot requested review from iitzIrFan and sanjay-kv as code owners July 8, 2026 22:34
@dependabot dependabot Bot added the javascript Pull requests that update javascript code label Jul 8, 2026
@dependabot
dependabot Bot requested a review from Adez017 as a code owner July 8, 2026 22:34
@vercel

vercel Bot commented Jul 8, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
recode-website Ready Ready Preview, Comment Jul 8, 2026 10:37pm

@github-actions

github-actions Bot commented Jul 8, 2026

Copy link
Copy Markdown

Thank you for submitting your pull request! 🙌 We'll review it as soon as possible. The estimated time for response is 5–8 hrs.

In the meantime, please provide all necessary screenshots and make sure you run - npm build run , command and provide a screenshot, a video recording, or an image of the update you made below, which helps speed up the review and assignment. If you have questions, reach out to LinkedIn. Your contributions are highly appreciated!😊

Note: I maintain the repo issue every day twice at 8:00 AM IST and 9:00 PM IST. If your PR goes stale for more than one day, you can tag and comment on this same issue by tagging @sanjay-kv.

We are here to help you on this journey of open source. Consistent 20 contributions are eligible for sponsorship 💰

🎁 check our list of amazing people we sponsored so far: GitHub Sponsorship. ✨

📚Your perks for contribution to this community 👇🏻

  1. Get free Consultation use code recode50 to get free: Mentorship for free.

  2. Get the Ebook for free use code recode at checkout: Data Science cheatsheet for Beginners.

  3. Check out this weekly Newsletter: Sanjay's Newsletter.

If there are any specific instructions or feedback regarding your PR, we'll provide them here. Thanks again for your contribution! 😊

@github-actions github-actions Bot added in-review The current changes are in review and would need approval and testing before merging level 1 10 points recode this is label for leaderboard labels Jul 8, 2026
@github-actions github-actions Bot added this to the recode:launch 3.0 milestone Jul 8, 2026
@sanjay-kv
sanjay-kv merged commit 71f9d23 into main Jul 9, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/npm_and_yarn/clerk/react-6.12.0 branch July 9, 2026 23:56
@github-actions

github-actions Bot commented Jul 9, 2026

Copy link
Copy Markdown

🎉 Your pull request has been successfully merged! 🎉 Thank you for your valuable contribution to our project.

I would be grateful if you can nominate for keeping this opensource project live and running Link to Nominate. Please do star the repo and Keep up the fantastic work! 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file in-review The current changes are in review and would need approval and testing before merging javascript Pull requests that update javascript code level 1 10 points recode this is label for leaderboard

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant