Skip to content

chore: bump @clerk/react from 6.12.11 to 6.14.3 - #2077

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/clerk/react-6.14.3
Open

chore: bump @clerk/react from 6.12.11 to 6.14.3#2077
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/npm_and_yarn/clerk/react-6.14.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 20, 2026

Copy link
Copy Markdown
Contributor

Bumps @clerk/react from 6.12.11 to 6.14.3.

Release notes

Sourced from @​clerk/react's releases.

@​clerk/react@​6.14.3

Patch Changes

  • Updated dependencies [7f5c294]:
    • @​clerk/shared@​4.29.1

@​clerk/react@​6.14.2

Patch Changes

Changelog

Sourced from @​clerk/react's changelog.

6.14.3

Patch Changes

  • Updated dependencies [7f5c294]:
    • @​clerk/shared@​4.29.1

6.14.2

Patch Changes

6.14.1

Patch Changes

  • Updated dependencies [131edec]:
    • @​clerk/shared@​4.28.1

6.14.0

Minor Changes

  • Add a way to supply a Clerk Protect assertion from your application, so a token minted by your own backend reaches Protect without your having to set a cookie. (#9313) by @​zourzouvillys

    A Protect assertion is a short-lived, signed token you create with the Clerk Backend API, carrying key/value pairs your Protect rules can read. Until now the only way to deliver one was the __clerk_protect_assertion cookie, which requires your app and Frontend API to be on the same site — true with a production CNAME setup, but not on development instances.

    Pass the token to Clerk and it is attached to sign-in and sign-up requests instead:

    // A token you already have.
    Clerk.load({ protectAssertion: token });
    // Or a function, re-read for each request.
    Clerk.load({ protectAssertion: () => sessionStorage.getItem('protect_assertion') ?? undefined });
    // Or set it later, once your app has fetched one.
    clerk.setProtectAssertion(token);

    Prefer the function form when a page can outlive the token. Assertions are short-lived by design, so a string captured at load time stops applying once it expires, whereas a function picks up a refreshed one.

    An assertion is an input to rules you author, never a decision on its own, and it applies only from the context you constrained it to when you minted it. Nothing about it can fail a sign-in: a resolver that throws, rejects, or returns anything other than a non-empty string simply results in no assertion being attached, and the request proceeds.

    The cookie continues to work unchanged. If both are present, the value supplied to the SDK wins.

Patch Changes

... (truncated)

Commits
  • 6c63025 ci(repo): Version packages (#9447)
  • 45514ca ci(repo): Version packages (#9402)
  • 195a09a ci(repo): Version packages (#9382)
  • d435282 ci(repo): Version packages (#9368)
  • aa86d9f feat(clerk-js,localizations,shared,ui): Add support for discounts/promo codes...
  • 52ec5cd feat(clerk-js,shared,react): supply a Protect assertion from the application ...
  • 6100719 ci(repo): Version packages (#9353)
  • a53c672 ci(repo): Version packages (#9334)
  • 58d8ff5 fix(react): Detect nested ClerkProvider via context instead of a global mount...
  • d639048 feat(js): add InviteMembersButton and Clerk.openInviteMembers (#9124)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@clerk/react](https://github.com/clerk/javascript/tree/HEAD/packages/react) from 6.12.11 to 6.14.3.
- [Release notes](https://github.com/clerk/javascript/releases)
- [Changelog](https://github.com/clerk/javascript/blob/main/packages/react/CHANGELOG.md)
- [Commits](https://github.com/clerk/javascript/commits/@clerk/react@6.14.3/packages/react)

---
updated-dependencies:
- dependency-name: "@clerk/react"
  dependency-version: 6.14.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 20, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Aug 20, 2026
@vercel

vercel Bot commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
recode-website Ready Ready Preview Aug 20, 2026 10:35pm

@github-actions

Copy link
Copy Markdown

Thank you for submitting your pull request! 🙌 We'll review it asap. The estimated time for response is 5–8 hrs.

In the meantime, please provide all necessary screenshots and make sure you run - npm build run , command and provide a screenshot, if it's a Video -LEGEND, which helps speed up the review. If you have questions, reach out to LinkedIn. You can see in our Leaderboard in 20 min from now!😊

Note: I maintain the repo issue every day twice at 8:00 AM IST and 9:00 PM IST. If your PR goes stale for more than one day, you can tag and comment on this same issue by tagging @sanjay-kv.

We are here to help you on this journey of open source. Consistent 20 contributions are eligible for sponsorship 💰

🎁 check our list of amazing people we sponsored so far: GitHub Sponsorship. ✨

📚Your perks for contribution to this community 👇🏻

  1. Get free Consultation after 5 PR: Mentorship for free.

  2. Get the Ebook for free after 10 PR: You can tag me in Discussion to get the same. Data Science cheatsheet for Beginners.

  3. Check out this weekly Newsletter: Sanjay's Newsletter.

Thanks again for your contribution! 😊

@github-actions github-actions Bot added in-review The current changes are in review and would need approval and testing before merging level 1 10 points recode this is label for leaderboard labels Aug 20, 2026
@github-actions github-actions Bot added this to the recode:launch 3.0 milestone Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file in-review The current changes are in review and would need approval and testing before merging javascript Pull requests that update javascript code level 1 10 points recode this is label for leaderboard

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants