Skip to content

build(ci): drop OTP 25, require OTP 27 or later - #36

Merged
maxekman merged 1 commit into
mainfrom
build/drop-otp-25
Sep 20, 2026
Merged

maxekman merged 1 commit into
mainfrom
build/drop-otp-25

Conversation

@maxekman

Copy link
Copy Markdown
Contributor

Companion to actioncard/a2a-elixir#69 — same matrix change, so the two libraries state one supported range instead of two. Simpler here: no jose pin, no Dependabot exception, no version bump.

Why

  • OTP 25 has had no patches, security fixes included, since May 2025 (16 months). Upstream maintains exactly three majors; today that's 29, 28, 27. OTP 26 reached EOL in May 2026.
  • Elixir itself dropped OTP 25 at v1.19 (Oct 2025). Elixir's only stated policy — "support the last three Erlang major versions" — resolves to OTP 27–29 today.
  • Peer libraries have already moved: req (OTP 27), hackney (27), bandit (26), finch (26).

Matrix

Same four cells, no extra CI cost. Each Elixir minor in the declared ~> 1.17 range paired with a maintained runtime:

Elixir OTP Why
1.17 27 Declared floor — proves ~> 1.17 is still real
1.18 27
1.19 28 Primary toolchain (what mise.toml resolves to locally)
1.20 29 Current/current

OTP 28 and 29 have never been tested here — including the OTP 28 this is developed on. quality, test-js and publish move to 1.19/28, which is a matrix cell, so they share warm deps/_build caches. The four hardcoded 1.18-27 cache-key strings in test-js move in lockstep — a stale key fails silently rather than loudly.

Note 1.18 + 28 would be invalid: Elixir 1.18 tops out at OTP 27, and setup-beam would silently resolve backwards to 1.18.4, the last 1.18 with an otp-28 build.

Verification

  • Elixir 1.19.5 / OTP 28: 400 tests pass with --warnings-as-errors; format and credo --strict clean; dialyzer run against a deleted priv/plts so a stale PLT couldn't mask anything — 0 errors cold.
  • Elixir 1.20.4 / OTP 28: compiles and passes 400 tests with --warnings-as-errors, format clean. Covers the new 1.20 cell's compiler and formatter risk without building OTP 29 locally. Unlike a2a-elixir, this repo needed no source fixes for 1.20.
  • mix bun test: 49 pass, 0 fail.
  • OTP 27 and 29 can't be reproduced locally; CI is the real check. The 1.17/27 cell matters most — it proves the declared floor still holds.

OTP 25 has had no patches, security fixes included, since May 2025, and
OTP 26 reached end of life in May 2026. Upstream maintains three majors
at a time, which today means 27 through 29, and Elixir itself dropped
OTP 25 in 1.19. Testing an unpatched runtime bought nothing.

The matrix now pairs each Elixir minor in the declared range with a
maintained runtime, covering OTP 28 and 29 for the first time. The
Elixir requirement is unchanged, so the floor cell still proves ~> 1.17
works. This mirrors the same change in a2a-elixir, keeping the two
libraries on one supported range.
@claude

claude Bot commented Sep 18, 2026

Copy link
Copy Markdown

Reviewed — no high-confidence issues found. LGTM.

@maxekman
maxekman merged commit 01308f4 into main Sep 20, 2026
8 checks passed
@maxekman
maxekman deleted the build/drop-otp-25 branch September 20, 2026 18:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant