---
collection: auth-identity
collection_name: Auth & Identity
digest_count: 10
canonical: https://releases.sh/collections/auth-identity/digest
---

# Auth & Identity weekly digests

- **[Security hardening at the foundation](https://releases.sh/collections/auth-identity/digest/2026-07-13)** — week of 2026-07-13 (94 releases)
  > Clerk patched a stored XSS vector in SSR script tags, locked down IPC origin validation in Electron, and announced TLS cipher suite deprecation, while the Clerk JS SDK gained timeout-based failure recovery for slow Frontend API endpoints.
- **[Hardening access: enforcement, federation, and fraud prevention](https://releases.sh/collections/auth-identity/digest/2026-07-06)** — week of 2026-07-06 (90 releases)
  > Auth0’s third-party apps for Organizations reached GA, Clerk enforced a token claim bypass, and both platforms added new fraud and federation controls.
- **[Browsers, bots, and billing](https://releases.sh/collections/auth-identity/digest/2026-06-29)** — week of 2026-06-29 (50 releases)
  > WorkOS shipped a browser-facing GraphQL API and an MCP server for AI management, Auth0 pushed SCIM provisioning to downstream apps via Event Streams, and Clerk added account credits UI and OAuth token revocation.
- **[Self-serve SSO and multi-project orgs reshape enterprise auth](https://releases.sh/collections/auth-identity/digest/2026-06-22)** — week of 2026-06-22 (67 releases)
  > WorkOS launched multiple Projects, Clerk enabled self-serve SSO for customer IT admins, and better-auth shipped a major OAuth provider restructuring — enterprise-grade auth capabilities moved further into developer tooling this week.
- **[OAuth consent comes home and Clerk enforces auth at lint time](https://releases.sh/collections/auth-identity/digest/2026-06-15)** — week of 2026-06-15 (68 releases)
  > Clerk ships a hostable OAuth consent component, an experimental ESLint plugin that catches unprotected Next.js routes, and exclusive organization membership, while Better Auth fixes OIDC claim overrides and Auth0's Refresh Token Metadata reaches GA for Enterprise customers.
- **[Better Auth hardens concurrent flows while Clerk standardises metadata APIs](https://releases.sh/collections/auth-identity/digest/2026-06-08)** — week of 2026-06-08 (75 releases)
  > Better Auth shipped fixes for dozens of race conditions and replay vulnerabilities across authentication flows, while Clerk deprecated unsafeMetadata in favour of dedicated updateMetadata methods and added new metadata replacement APIs to its backend SDK.
- **[The week M2M went multi-tenant and SCIM closed the loop](https://releases.sh/collections/auth-identity/digest/2026-06-01)** — week of 2026-06-01 (41 releases)
  > Auth0 shipped machine-to-machine access for third-party applications and made Inbound SCIM Groups generally available, while Clerk rolled out prebuilt organization management UI across its native mobile SDKs and a major backend API update.
- **[Debugging emails, hardening auth, and SSO everywhere](https://releases.sh/collections/auth-identity/digest/2026-05-25)** — week of 2026-05-25 (59 releases)
  > Clerk launched Email Logs in public beta for debugging delivery issues, while Better Auth patched several high-severity security flaws. Auth0 shipped GA passkeys with cross-subdomain support and organization-scoped Token Vault, and Clerk added self-serve SSO configuration across its SDKs.
- **[Js-cookie security fix ripples across every Clerk SDK](https://releases.sh/collections/auth-identity/digest/2026-05-18)** — week of 2026-05-18 (87 releases)
  > Every Clerk JavaScript SDK patched this week to upgrade js-cookie to 3.0.7, addressing a cross-site scripting vulnerability. Meanwhile, a new UI helper fixes subscription button visibility for seat-based plans without a base fee.
- **[Clerk patches a Next.js bypass, ships SSO UI, and adds metadata updates](https://releases.sh/collections/auth-identity/digest/2026-05-11)** — week of 2026-05-11 (48 releases)
  > The week's biggest story is a high-severity Next.js App Router middleware bypass fixed in Clerk's Next.js SDK, while across the JavaScript monorepo the team shipped SAML SSO configuration steps, user metadata APIs, new UI customization options, and a WorkOS feature flags runtime client.

## Fetching more

Append `.md` (markdown), `.json` (raw data), or `.atom` (feed) to any URL on this page.

- Digest Atom feed: `https://releases.sh/collections/auth-identity/digest.atom`
