Skip to content

chore(repo): Update security policy - #9697

Merged
dominic-clerk merged 2 commits into
mainfrom
dc-update-security-policy
Sep 9, 2026
Merged

chore(repo): Update security policy#9697
dominic-clerk merged 2 commits into
mainfrom
dc-update-security-policy

Conversation

@dominic-clerk

Copy link
Copy Markdown
Contributor

Description

Updates the security policy to point at the website. This file will be copied across our open source repos.

Checklist

  • pnpm test runs as expected.
  • pnpm build runs as expected.
  • (If applicable) JSDoc comments have been added or updated for any package exports
  • (If applicable) Documentation has been updated

Type of change

  • 🐛 Bug fix
  • 🌟 New feature
  • 🔨 Breaking change
  • 📖 Refactoring / dependency upgrade / documentation
  • other:

@changeset-bot

changeset-bot Bot commented Sep 9, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 8a06fbc

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 0 packages

When changesets are added to this PR, you'll see the packages that this PR includes changesets for and the associated semver types

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@vercel

vercel Bot commented Sep 9, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
clerk-js-sandbox Ready Ready Preview Sep 9, 2026 8:10pm UTC
swingset Ready Ready Preview Sep 9, 2026 8:10pm UTC

Request Review

@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Review Change StackReview Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: ASSERTIVE

Plan: Team

Run ID: 3e1b974a-bc0d-48c1-a7fb-a0625a46c169

📥 Commits

Reviewing files that changed from the base of the PR and between 06be25f and 8a06fbc.

📒 Files selected for processing (2)
  • .changeset/plenty-pots-lose.md
  • docs/SECURITY.md
🔗 Linked repositories identified

CodeRabbit considers these linked repositories for cross-repo context during reviews:

  • clerk/clerk_go (manual)
  • clerk/dashboard (manual)
  • clerk/accounts (manual)
  • clerk/backoffice (manual)
  • clerk/clerk (manual)

Included review availability: 6 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 10 reviews per hour.


📝 Walkthrough

Walkthrough

The security policy now links to Clerk’s security page and vulnerability disclosure policy. The previous email-based reporting instructions and disclosure guidance were removed. A Changeset frontmatter block was added.

Priority: ⬇️ Low

Estimated code review effort: 1 (Trivial) | ~3 minutes

Merge Risk: ⚪ Minimal · up to 8a06f

The security policy now directs users to Clerk’s current security and vulnerability disclosure resources, with no identified merge-blocking risk.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely describes the main change: updating the repository security policy.
Description check ✅ Passed The description explains that the security policy now points to the website and states that the file will be copied across open-source repositories.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

Warning

Linked repositories: Your configuration references 7 linked repositories, but your current plan allows 5. Analyzed clerk/clerk_go, clerk/dashboard, clerk/accounts, clerk/backoffice, clerk/clerk, skipped clerk/clerk-docs, clerk/cloudflare-workers.


Comment @coderabbitai help to get the list of available commands.

@pkg-pr-new

pkg-pr-new Bot commented Sep 9, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@9697

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@9697

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@9697

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@9697

@clerk/electron

npm i https://pkg.pr.new/@clerk/electron@9697

@clerk/electron-passkeys

npm i https://pkg.pr.new/@clerk/electron-passkeys@9697

@clerk/eslint-plugin

npm i https://pkg.pr.new/@clerk/eslint-plugin@9697

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@9697

@clerk/expo-google-signin

npm i https://pkg.pr.new/@clerk/expo-google-signin@9697

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@9697

@clerk/express

npm i https://pkg.pr.new/@clerk/express@9697

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@9697

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@9697

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@9697

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@9697

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@9697

@clerk/react

npm i https://pkg.pr.new/@clerk/react@9697

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@9697

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@9697

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@9697

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@9697

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@9697

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@9697

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@9697

commit: 8a06fbc

@dominic-clerk dominic-clerk changed the title chore: Update security policy chore(repo): Update security policy Sep 9, 2026
@dominic-clerk
dominic-clerk force-pushed the dc-update-security-policy branch from b683686 to 8a06fbc Compare September 9, 2026 20:07
@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Note

GitHub couldn't provide a complete incremental comparison for this pull request, so CodeRabbit is performing a full review instead. This review may take a little longer.

@dominic-clerk
dominic-clerk enabled auto-merge (squash) September 9, 2026 22:02
@dominic-clerk
dominic-clerk merged commit 3f40ad9 into main Sep 9, 2026
81 of 82 checks passed
@dominic-clerk
dominic-clerk deleted the dc-update-security-policy branch September 9, 2026 22:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants