Remove Clerk-internal host from default CSP directive
Removed https://images.clerkstage.dev from the default connect-src Content Security Policy directive as it is an internal Clerk storage host not used by applications. Organization logos continue to be served from https://img.clerk.com.
Patch Changes
-
Remove
https://images.clerkstage.devfrom the defaultconnect-srcContent Security Policy directive. It is a Clerk-internal storage host that no application connects to. Organization logos are served fromhttps://img.clerk.com, which stays in the default. (#9898) by @Grundlefleck -
Updated dependencies [
2302140,2654caa,dee649c]:- @clerk/backend@3.23.0
- @clerk/shared@4.39.0
- @clerk/react@6.17.6
Source: original entry ↗
More from Clerk
Follow Clerk to get its new changes in your feed and email digest.
@clerk/nuxt@3.1.11
Patch release updating internal dependencies for @clerk/shared, @clerk/backend, and @clerk/vue to their latest versions.
@clerk/ui dependency updates
Updated @clerk/shared and @clerk/localizations dependencies to their latest patch versions.
@clerk/nextjs 7.9.12
Patch release updating internal dependencies including @clerk/react, @clerk/shared, and @clerk/backend to their latest versions.