Skip to content

chore(clerk-js): remove redundant dequal dependency#8608

Open
jacekradko wants to merge 3 commits into
mainfrom
jacek/aisec-32-f-281-clerkclerk-js-remove-redundant-dequal-runtime
Open

chore(clerk-js): remove redundant dequal dependency#8608
jacekradko wants to merge 3 commits into
mainfrom
jacek/aisec-32-f-281-clerkclerk-js-remove-redundant-dequal-runtime

Conversation

@jacekradko

@jacekradko jacekradko commented May 21, 2026

Copy link
Copy Markdown
Member

Nothing in @clerk/clerk-js imports dequal directly. It was listed as a direct runtime dependency but is only reached transitively through @clerk/shared (useDeepEqualMemo). Drop it from packages/clerk-js/package.json and the lockfile, with a patch changeset.

Resolves AISEC-32. Thanks to @7188ce06 for reporting.

@vercel

vercel Bot commented May 21, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
clerk-js-sandbox Ready Ready Preview, Comment Jun 3, 2026 5:31pm

Request Review

@changeset-bot

changeset-bot Bot commented May 21, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 05a9257

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 3 packages
Name Type
@clerk/clerk-js Patch
@clerk/chrome-extension Patch
@clerk/expo Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@jacekradko jacekradko marked this pull request as ready for review May 21, 2026 01:28
@coderabbitai

coderabbitai Bot commented May 21, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository YAML (base), Organization UI (inherited)

Review profile: CHILL

Plan: Pro

Run ID: 18c77492-6b5e-4489-ba23-ec3457bbe0f4

📥 Commits

Reviewing files that changed from the base of the PR and between faa16d3 and 05a9257.

⛔ Files ignored due to path filters (1)
  • pnpm-lock.yaml is excluded by !**/pnpm-lock.yaml
📒 Files selected for processing (1)
  • packages/clerk-js/package.json
✅ Files skipped from review due to trivial changes (1)
  • packages/clerk-js/package.json

📝 Walkthrough

Walkthrough

This PR removes a redundant direct dequal dependency from the @clerk/clerk-js package by deleting it from package.json and adds a changeset documenting the removal and a patch version bump.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title accurately describes the main change: removing the redundant dequal dependency from the clerk-js package. It is concise, specific, and directly relates to the changeset.
Description check ✅ Passed The description is directly related to the changeset, explaining why dequal is redundant (only transitively needed through @clerk/shared) and references the issue being resolved.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.


Comment @coderabbitai help to get the list of available commands and usage tips.

@pkg-pr-new

pkg-pr-new Bot commented May 21, 2026

Copy link
Copy Markdown

Open in StackBlitz

@clerk/astro

npm i https://pkg.pr.new/@clerk/astro@8608

@clerk/backend

npm i https://pkg.pr.new/@clerk/backend@8608

@clerk/chrome-extension

npm i https://pkg.pr.new/@clerk/chrome-extension@8608

@clerk/clerk-js

npm i https://pkg.pr.new/@clerk/clerk-js@8608

@clerk/expo

npm i https://pkg.pr.new/@clerk/expo@8608

@clerk/expo-passkeys

npm i https://pkg.pr.new/@clerk/expo-passkeys@8608

@clerk/express

npm i https://pkg.pr.new/@clerk/express@8608

@clerk/fastify

npm i https://pkg.pr.new/@clerk/fastify@8608

@clerk/hono

npm i https://pkg.pr.new/@clerk/hono@8608

@clerk/localizations

npm i https://pkg.pr.new/@clerk/localizations@8608

@clerk/nextjs

npm i https://pkg.pr.new/@clerk/nextjs@8608

@clerk/nuxt

npm i https://pkg.pr.new/@clerk/nuxt@8608

@clerk/react

npm i https://pkg.pr.new/@clerk/react@8608

@clerk/react-router

npm i https://pkg.pr.new/@clerk/react-router@8608

@clerk/shared

npm i https://pkg.pr.new/@clerk/shared@8608

@clerk/tanstack-react-start

npm i https://pkg.pr.new/@clerk/tanstack-react-start@8608

@clerk/testing

npm i https://pkg.pr.new/@clerk/testing@8608

@clerk/ui

npm i https://pkg.pr.new/@clerk/ui@8608

@clerk/upgrade

npm i https://pkg.pr.new/@clerk/upgrade@8608

@clerk/vue

npm i https://pkg.pr.new/@clerk/vue@8608

commit: 05a9257

@wobsoriano

wobsoriano commented May 21, 2026

Copy link
Copy Markdown
Member

@jacekradko, this PR will use dequal 😃 #8587

(I already reviewed and approved the PR, but if you have bandwidth for a quick scan, Id appreciate it.)

@alexcarpenter alexcarpenter self-requested a review May 21, 2026 12:30
@github-actions

Copy link
Copy Markdown
Contributor

Snapi: no API changes detected in @clerk/backend, @clerk/clerk-js, @clerk/nextjs, @clerk/react, @clerk/shared, @clerk/ui.

@github-actions

github-actions Bot commented Jun 3, 2026

Copy link
Copy Markdown
Contributor

API Changes Report

Generated by Break Check on 2026-06-03T17:33:45.204Z

Summary

Metric Count
Packages analyzed 19
Packages with changes 1
🔴 Breaking changes 0
🟡 Non-breaking changes 1
🟢 Additions 0

🤖 This report was reviewed by claude-sonnet-4-6.

Note
Break Check could not snapshot 3 subpaths; the diff below excludes them.

  • @clerk/astro ./env: Internal Error: Unable to determine module for: /home/runner/_work/javascript/javascript/packages/astro/env.d.ts You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/shared ./cookie: Internal Error: Unable to follow symbol for "Cookies" You have encountered a software defect. Please consider reporting the issue to the maintainers of this application.
  • @clerk/testing ./cypress: Symbol not found for identifier: Cypress

@clerk/shared

Current version: 4.15.0
Recommended bump: MINOR → 4.16.0

Subpath ./apiUrlFromPublishableKey

🟡 Non-breaking Changes (1)

Modified: apiUrlFromPublishableKey
- apiUrlFromPublishableKey: (publishableKey: string) => "https://api.lclclerk.com" | "https://api.clerkstage.dev" | "https://api.clerk.com"
+ apiUrlFromPublishableKey: (publishableKey: string) => "https://api.clerk.com" | "https://api.lclclerk.com" | "https://api.clerkstage.dev"

Static analyzer: Breaking change in function apiUrlFromPublishableKey: Return type changed: "https://api.lclclerk.com"|"https://api.clerkstage.dev"|"https://api.clerk.com""https://api.clerk.com"|"https://api.lclclerk.com"|"https://api.clerkstage.dev"

🤖 AI review (reclassified as non-breaking) (99%): The union members are identical; only their order changed, and TypeScript union types are order-independent — no well-typed consumer code can break from this reordering.


Report generated by Break Check

Last ran on 05a9257. Pushes that change no tracked declarations (no API surface change vs. base) are skipped and don't update this comment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants