Require Finch 0.24 and take mint 1.11: end the mint 1.10.1 hold - #264
Merged
Merged
Conversation
Finch 0.24.0 closes an HTTP/1 connection after a request or response error instead of returning it to its pool (sneako/finch#397), so mint 1.11.0's open-after-timeout connection is no longer reused. The lock and the example projects' locks move to finch 0.24.0, mint 1.11.0 and hpax 1.1.0; mix.exs requires finch ~> 0.24 so a consumer cannot resolve Finch 0.23 with mint 1.11. The three mint advisories leave .audit_ignore and the Known limits entry leaves the release notes. Refs #263
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #263.
Finch 0.24.0 (released 2026-09-29) contains sneako/finch#397: it closes an HTTP/1 connection after a request or response error instead of returning it to its pool. That was the condition recorded for ending the mint 1.10.1 hold.
What changed
mix.lock,examples/deployment/mix.lockandexamples/workspace_agent/mix.lockmove to finch 0.24.0, mint 1.11.0 and hpax 1.1.0 (mix deps.update finch mint hpax; no other package moves).{:finch, "~> 0.21"}becomes{:finch, "~> 0.24"}. With~> 0.21a consumer could still resolve Finch 0.23.0 together with mint 1.11.0, the pair that fails. Imp already declares Finch directly (it matches Finch's error structs), so raising the floor there is enough;mintstays~> 1.8, Finch's own requirement. Themix.exscomments now say why 0.24 is the floor and drop the hold..audit_ignore: the mint block and its three ids (EEF-CVE-2026-91043, -92103, -94194) are removed.RELEASE_NOTES.md;CHANGELOG.mdgets an Unreleased / Security entry with the migration (drop a{:mint, "~> 1.10.1"}pin;mix deps.update finch mint hpax). README anddocs/had no entry.test/timed_out_connection_test.exsdescribes the behaviour it holds rather than the hold.decisions.mdhad no line for the hold, so nothing there changes.research/matched_instruction_optimizers_trec/mix.lockis left as it is: it records an older run's dependency set (req 0.6.3, mint 1.9.3), and updating it pulls in some thirty unrelated packages.Evidence (run locally, 2026-09-29)
mix test test/timed_out_connection_test.exson the new lock:1 test, 0 failures.{:finch, "== 0.23.0"}and{:mint, "== 1.11.0"}(lock: finch 0.23.0, mint 1.11.0, hpax 1.1.0):1 test, 1 failure. The second call returns{:error, %Imp.LMError{reason: %CaseClauseError{term: {:status, ref, 200}}}}at line 77. Then restoredmix.exsandmix.lockand re-ran:1 test, 0 failures.mix check:59 doctests, 9 properties, 3562 tests, 0 failures, 13 skipped (221 excluded).mix quality.check: credo found no issues;mix deps.audit --ignore-file .audit_ignore: "No vulnerabilities found";mix hex.auditpasses, ignoring only the two cowlib ids (EEF-CVE-2026-43966, -43969), which are unrelated to this change. Plainmix deps.auditwith no ignore file: "No vulnerabilities found".mix docs.check,mix dialyzer.check,mix package.check: pass.Not run: the integration, protocol, differential and livebook-execute CI lanes, and no live provider calls.