Skip to content

Require Finch 0.24 and take mint 1.11: end the mint 1.10.1 hold - #264

Merged
deepfates merged 2 commits into
mainfrom
claude/end-mint-hold
Sep 29, 2026
Merged

deepfates merged 2 commits into
mainfrom
claude/end-mint-hold

Conversation

@deepfates

Copy link
Copy Markdown
Owner

Closes #263.

Finch 0.24.0 (released 2026-09-29) contains sneako/finch#397: it closes an HTTP/1 connection after a request or response error instead of returning it to its pool. That was the condition recorded for ending the mint 1.10.1 hold.

What changed

  • Lock: mix.lock, examples/deployment/mix.lock and examples/workspace_agent/mix.lock move to finch 0.24.0, mint 1.11.0 and hpax 1.1.0 (mix deps.update finch mint hpax; no other package moves).
  • Requirement: {:finch, "~> 0.21"} becomes {:finch, "~> 0.24"}. With ~> 0.21 a consumer could still resolve Finch 0.23.0 together with mint 1.11.0, the pair that fails. Imp already declares Finch directly (it matches Finch's error structs), so raising the floor there is enough; mint stays ~> 1.8, Finch's own requirement. The mix.exs comments now say why 0.24 is the floor and drop the hold.
  • .audit_ignore: the mint block and its three ids (EEF-CVE-2026-91043, -92103, -94194) are removed.
  • Docs: the mint/Finch Known limits entry and the Install paragraph pointing at it are removed from RELEASE_NOTES.md; CHANGELOG.md gets an Unreleased / Security entry with the migration (drop a {:mint, "~> 1.10.1"} pin; mix deps.update finch mint hpax). README and docs/ had no entry.
  • Test comment: test/timed_out_connection_test.exs describes the behaviour it holds rather than the hold.
  • decisions.md had no line for the hold, so nothing there changes.
  • research/matched_instruction_optimizers_trec/mix.lock is left as it is: it records an older run's dependency set (req 0.6.3, mint 1.9.3), and updating it pulls in some thirty unrelated packages.

Evidence (run locally, 2026-09-29)

  • mix test test/timed_out_connection_test.exs on the new lock: 1 test, 0 failures.
  • Temporarily pinned {:finch, "== 0.23.0"} and {:mint, "== 1.11.0"} (lock: finch 0.23.0, mint 1.11.0, hpax 1.1.0): 1 test, 1 failure. The second call returns {:error, %Imp.LMError{reason: %CaseClauseError{term: {:status, ref, 200}}}} at line 77. Then restored mix.exs and mix.lock and re-ran: 1 test, 0 failures.
  • mix check: 59 doctests, 9 properties, 3562 tests, 0 failures, 13 skipped (221 excluded).
  • mix quality.check: credo found no issues; mix deps.audit --ignore-file .audit_ignore: "No vulnerabilities found"; mix hex.audit passes, ignoring only the two cowlib ids (EEF-CVE-2026-43966, -43969), which are unrelated to this change. Plain mix deps.audit with no ignore file: "No vulnerabilities found".
  • mix docs.check, mix dialyzer.check, mix package.check: pass.
  • Both example projects compile on their new locks.

Not run: the integration, protocol, differential and livebook-execute CI lanes, and no live provider calls.

Finch 0.24.0 closes an HTTP/1 connection after a request or response error
instead of returning it to its pool (sneako/finch#397), so mint 1.11.0's
open-after-timeout connection is no longer reused. The lock and the example
projects' locks move to finch 0.24.0, mint 1.11.0 and hpax 1.1.0; mix.exs
requires finch ~> 0.24 so a consumer cannot resolve Finch 0.23 with mint 1.11.
The three mint advisories leave .audit_ignore and the Known limits entry
leaves the release notes.

Refs #263
@deepfates
deepfates merged commit 4e90bd9 into main Sep 29, 2026
10 checks passed
@deepfates
deepfates deleted the claude/end-mint-hold branch September 29, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

End the mint 1.10.1 hold: Finch 0.24.0 contains the fix

1 participant