releases.shpreview

BetaWeekly digests are a beta — we're trying something new. Feedback welcome.

Auth & Identity weekly digests

  • Week of July 13, 2026
    Security hardening at the foundation

    Clerk patched a stored XSS vector in SSR script tags, locked down IPC origin validation in Electron, and announced TLS cipher suite deprecation, while the Clerk JS SDK gained timeout-based failure recovery for slow Frontend API endpoints.

  • Week of July 6, 2026
    Hardening access: enforcement, federation, and fraud prevention

    Auth0’s third-party apps for Organizations reached GA, Clerk enforced a token claim bypass, and both platforms added new fraud and federation controls.

  • Week of June 29, 2026
    Browsers, bots, and billing

    WorkOS shipped a browser-facing GraphQL API and an MCP server for AI management, Auth0 pushed SCIM provisioning to downstream apps via Event Streams, and Clerk added account credits UI and OAuth token revocation.

  • Week of June 22, 2026
    Self-serve SSO and multi-project orgs reshape enterprise auth

    WorkOS launched multiple Projects, Clerk enabled self-serve SSO for customer IT admins, and better-auth shipped a major OAuth provider restructuring — enterprise-grade auth capabilities moved further into developer tooling this week.

  • Week of June 15, 2026
    OAuth consent comes home and Clerk enforces auth at lint time

    Clerk ships a hostable OAuth consent component, an experimental ESLint plugin that catches unprotected Next.js routes, and exclusive organization membership, while Better Auth fixes OIDC claim overrides and Auth0's Refresh Token Metadata reaches GA for Enterprise customers.

  • Week of June 8, 2026
    Better Auth hardens concurrent flows while Clerk standardises metadata APIs

    Better Auth shipped fixes for dozens of race conditions and replay vulnerabilities across authentication flows, while Clerk deprecated unsafeMetadata in favour of dedicated updateMetadata methods and added new metadata replacement APIs to its backend SDK.

  • Week of June 1, 2026
    The week M2M went multi-tenant and SCIM closed the loop

    Auth0 shipped machine-to-machine access for third-party applications and made Inbound SCIM Groups generally available, while Clerk rolled out prebuilt organization management UI across its native mobile SDKs and a major backend API update.

  • Week of May 25, 2026
    Debugging emails, hardening auth, and SSO everywhere

    Clerk launched Email Logs in public beta for debugging delivery issues, while Better Auth patched several high-severity security flaws. Auth0 shipped GA passkeys with cross-subdomain support and organization-scoped Token Vault, and Clerk added self-serve SSO configuration across its SDKs.

  • Week of May 18, 2026
    Js-cookie security fix ripples across every Clerk SDK

    Every Clerk JavaScript SDK patched this week to upgrade js-cookie to 3.0.7, addressing a cross-site scripting vulnerability. Meanwhile, a new UI helper fixes subscription button visibility for seat-based plans without a base fee.

  • Week of May 11, 2026
    Clerk patches a Next.js bypass, ships SSO UI, and adds metadata updates

    The week's biggest story is a high-severity Next.js App Router middleware bypass fixed in Clerk's Next.js SDK, while across the JavaScript monorepo the team shipped SAML SSO configuration steps, user metadata APIs, new UI customization options, and a WorkOS feature flags runtime client.