megachangelog
Improvement7.9.11

Remove Clerk-internal host from default CSP directive

Removed https://images.clerkstage.dev from the default connect-src Content Security Policy directive as it is an internal Clerk storage host not used by applications. Organization logos continue to be served from https://img.clerk.com.

Patch Changes

  • Remove https://images.clerkstage.dev from the default connect-src Content Security Policy directive. It is a Clerk-internal storage host that no application connects to. Organization logos are served from https://img.clerk.com, which stays in the default. (#9898) by @Grundlefleck

  • Updated dependencies [2302140, 2654caa, dee649c]:

    • @clerk/backend@3.23.0
    • @clerk/shared@4.39.0
    • @clerk/react@6.17.6
securitycspnextjspatch

Source: original entry ↗

More from Clerk

Follow Clerk to get its new changes in your feed and email digest.

Improvement3.1.11

@clerk/nuxt@3.1.11

Patch release updating internal dependencies for @clerk/shared, @clerk/backend, and @clerk/vue to their latest versions.

nuxtdependenciespatch
Improvement1.39.1

@clerk/ui dependency updates

Updated @clerk/shared and @clerk/localizations dependencies to their latest patch versions.

dependenciesuilocalization
Improvement7.9.12

@clerk/nextjs 7.9.12

Patch release updating internal dependencies including @clerk/react, @clerk/shared, and @clerk/backend to their latest versions.

nextjsdependenciespatch
See all Clerk changes →