Skip to content

build(deps-dev): bump @clerk/shared from 4.30.2 to 4.36.0 - #503

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/clerk/shared-4.36.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/bun/clerk/shared-4.36.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps @clerk/shared from 4.30.2 to 4.36.0.

Release notes

Sourced from @​clerk/shared's releases.

@​clerk/shared@​4.36.0

Minor Changes

  • <SignIn /> and <SignUp /> show a dedicated screen when a request is blocked, with a reference the user can quote to support. (#9600) by @​zourzouvillys

    action_blocked errors now expose traceId, title, description, linkUrl, linkText, kind and data on meta.

Patch Changes

  • Fix enterprise SSO sign-ins erroring instead of showing a verification challenge raised while handing off to the identity provider. (#9619) by @​zourzouvillys

    If you use the prebuilt <SignIn /> component, there is nothing to do. If you have Clerk Protect enabled and call signIn.authenticateWithRedirect() or signIn.authenticateWithPopup() from a custom sign-in flow, catch a ClerkRuntimeError with code protect_check_required and show the verification challenge, to avoid a stalled sign-in.

    That error means a verification challenge has to be completed before the sign-in can redirect. It replaces the generic "not supported" error these methods threw before. When it is thrown, the sign-in is gated: signIn.protectCheck is set, or its status is needs_protect_check. For enterprise SSO, run the challenge and then call authenticateWithRedirect() again with continueSignIn: true. If the server has already prepared the redirect, the sign-in continues to the identity provider and the challenge runs when it returns, so no error is thrown.

  • Run a sign-up's verification challenge before handing off to an enterprise connection, matching the order used elsewhere in the flow. (#9622) by @​zourzouvillys

@​clerk/shared@​4.34.0

Minor Changes

  • Add @clerk/shared/phone with Clerk's country metadata and phone-number parsing, formatting, and detection helpers. (#9763) by @​Ephem

  • Rename the SSO fallback sign-in flow to SSO bypass, matching the name the feature ships under. The sign-in resource's ssoFallbackFirstFactors is now ssoBypassFirstFactors and reads the sso_bypass_first_factors field from the API, the signIn.ssoFallback localization keys are now signIn.ssoBypass, and the ssoFallback card action element id is now ssoBypass. The flow has not been enabled on any instance, so no application is affected by the old names going away. (#9822) by @​mauricioabreu

  • Add the ability for Organization admins to manage the SSO bypass allowlist from the Security page of <OrganizationProfile />. (#9809) by @​mauricioabreu

    For custom flows, organization.ssoBypassAllowlist exposes getUsers(), addUser({ userId }) and removeUser(userId).

  • Add createDynamicParamParser and populateParamFromObject to @clerk/shared/url for resolving :property placeholders in URL templates. (#9761) by @​Ephem

Patch Changes

  • Each enterprise connection listed on the organization Security page now opens its own page. It lists the connection name and domains, the service provider values to copy into the identity provider, the identity provider configuration behind an Edit form, and the connection settings as a form you save. The header carries one action, either Activate or Continue setup, and deactivating or removing the connection lives in a Danger zone section at the bottom of the page. The row menu is gone; click the row instead. (#9748) by @​NicolasLopes7

    The setup wizard's domains step now shows a checkbox per verified domain, so an admin picks which domains a connection covers. A domain another connection of the organization already authenticates is disabled and labelled with that connection's name, and an error from creating the connection is shown on the provider step instead of being dropped.

    New customization handles ship with it: the organizationProfileSecuritySsoConnectionRow and organizationProfileSecuritySsoConnectionPage appearance elements, the configureSSOVerifyDomainCardCheckbox element, the claimed badge id, the new FieldId values for the connection settings, and the ssoConnectionName, ssoConnectionDomains, ssoConnectionServiceProvider, ssoConnectionIdentityProvider, ssoConnectionSettings and ssoConnectionDangerZone ProfileSectionId values.

@​clerk/shared@​4.33.0

Minor Changes

  • Add agentid to OAuthProvider and OAUTH_PROVIDERS to support the "Continue with AgentID" OAuth flow. Instances with the connection enabled now render a "Continue with AgentID" button, with the AgentID mark tinted to match the theme's foreground color so it stays legible in dark mode. (#9735) by @​wyattjoh

Patch Changes

  • The organization Security page now lists every enterprise SSO connection of the organization, each with its own status, domains, and actions. The SSO wizard edits one explicit connection, and a banner names it when the organization has more than one. Changing a provider or removing a connection now targets that connection instead of the first one returned by the API. (#9729) by @​NicolasLopes7

@​clerk/shared@​4.32.0

Minor Changes

... (truncated)

Changelog

Sourced from @​clerk/shared's changelog.

4.36.0

Minor Changes

  • <SignIn /> and <SignUp /> show a dedicated screen when a request is blocked, with a reference the user can quote to support. (#9600) by @​zourzouvillys

    action_blocked errors now expose traceId, title, description, linkUrl, linkText, kind and data on meta.

Patch Changes

  • Fix enterprise SSO sign-ins erroring instead of showing a verification challenge raised while handing off to the identity provider. (#9619) by @​zourzouvillys

    If you use the prebuilt <SignIn /> component, there is nothing to do. If you have Clerk Protect enabled and call signIn.authenticateWithRedirect() or signIn.authenticateWithPopup() from a custom sign-in flow, catch a ClerkRuntimeError with code protect_check_required and show the verification challenge, to avoid a stalled sign-in.

    That error means a verification challenge has to be completed before the sign-in can redirect. It replaces the generic "not supported" error these methods threw before. When it is thrown, the sign-in is gated: signIn.protectCheck is set, or its status is needs_protect_check. For enterprise SSO, run the challenge and then call authenticateWithRedirect() again with continueSignIn: true. If the server has already prepared the redirect, the sign-in continues to the identity provider and the challenge runs when it returns, so no error is thrown.

  • Run a sign-up's verification challenge before handing off to an enterprise connection, matching the order used elsewhere in the flow. (#9622) by @​zourzouvillys

4.35.0

Minor Changes

  • The "Add members" card on the SSO allow list page of <OrganizationProfile /> now offers two ways to add people: by email address, or every member with a given role at once. Members whose email address is not served by one of the organization's enterprise connections are skipped. When nothing could be added the card stays open and says why, and when some were added it moves to a success step that reports how many were skipped. (#9826) by @​mauricioabreu

    For custom flows, organization.ssoBypassAllowlist gains addUsers({ userIds }), which calls the new bulk endpoint in batches of 100 and returns the added entries together with the users that could not be added and why.

    Inputs marked to be ignored by password managers now also carry the Bitwarden, LastPass and Dashlane opt-out attributes, so those extensions stop offering to fill fields such as the allow list email address.

    The member picker that the "Add member" card shipped with in 4.18.0 is gone, and so are its localization keys under organizationProfile.securityPage.ssoBypassPage.addForm: memberLabel, memberPlaceholder, changeButton and noResults. The feature was never enabled on any instance, so no application depends on them.

    New customization handles: the organizationProfileSecuritySsoBypassEmailInput, organizationProfileSecuritySsoBypassRoleWarning, organizationProfileSecuritySsoBypassFailure and organizationProfileSecuritySsoBypassBulkResult appearance elements.

  • Localize icon-only social sign-in button names using socialButtonsBlockButton and exclude decorative provider icons from the accessibility tree. Add formFieldAction__showPassword and formFieldAction__hidePassword localization keys for password visibility controls, with translations for every supported locale and English fallback for older localization resources. (#9897) by @​jigar-clerk

Patch Changes

  • Show the provider logo next to each connection name on the enterprise account chooser. (#9895) by @​NicolasLopes7

  • Missing and invalid key errors now list the Clerk CLI commands that fix them: npx clerk@latest init for a new app, npx clerk@latest link and npx clerk@latest env pull for an existing one, and npx clerk@latest env pull --instance prod for production keys. The missing secret key error skips init, since the publishable key already points to an existing app. (#9848) by @​eatmorespinach

4.34.0

Minor Changes

  • Add @clerk/shared/phone with Clerk's country metadata and phone-number parsing, formatting, and detection helpers. (#9763) by @​Ephem

  • Rename the SSO fallback sign-in flow to SSO bypass, matching the name the feature ships under. The sign-in resource's ssoFallbackFirstFactors is now ssoBypassFirstFactors and reads the sso_bypass_first_factors field from the API, the signIn.ssoFallback localization keys are now signIn.ssoBypass, and the ssoFallback card action element id is now ssoBypass. The flow has not been enabled on any instance, so no application is affected by the old names going away. (#9822) by @​mauricioabreu

  • Add the ability for Organization admins to manage the SSO bypass allowlist from the Security page of <OrganizationProfile />. (#9809) by @​mauricioabreu

... (truncated)

Commits
  • 750e7fc ci(repo): Version packages (#9931)
  • 645a532 feat(ui,shared,localizations): dedicated screen for a blocked request (#9600)
  • 4e538ac fix(shared): run a sign-up challenge before the enterprise hand-off (#9622)
  • 84ee588 fix(clerk-js,ui): show the challenge raised while handing off to an enterpris...
  • 8bca915 ci(repo): Version packages (#9893)
  • b3af79e feat(ui): show provider logo on enterprise connection chooser (#9895)
  • d46b544 feat(ui,clerk-js,shared,localizations): Add all members of a role to the SSO ...
  • f50f48c fix(ui,localizations): localize authentication accessible labels (#9897)
  • cc6f11a fix(shared): Reword error messaging when missing or invalid keys (#9848)
  • 0a15af9 ci(repo): Version packages (#9782)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [@clerk/shared](https://github.com/clerk/javascript/tree/HEAD/packages/shared) from 4.30.2 to 4.36.0.
- [Release notes](https://github.com/clerk/javascript/releases)
- [Changelog](https://github.com/clerk/javascript/blob/main/packages/shared/CHANGELOG.md)
- [Commits](https://github.com/clerk/javascript/commits/@clerk/shared@4.36.0/packages/shared)

---
updated-dependencies:
- dependency-name: "@clerk/shared"
  dependency-version: 4.36.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels Sep 30, 2026
@changeset-bot

changeset-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

⚠️ No Changeset found

Latest commit: fe801d1

Merging this PR will not cause a version bump for any packages. If these changes should not result in a new version, you're good to go. If these changes should result in a version bump, you need to add a changeset.

This PR includes no changesets

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Click here to learn what changesets are, and how to add one.

Click here if you're a maintainer who wants to add a changeset to this PR

@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 4f2fc012-5f99-48ca-8c28-21bcb47c36b4

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants