Skip to content

build(deps): require a2a ~> 0.3.0 - #37

Merged
maxekman merged 2 commits into
mainfrom
max/a2a-0-3-0
Sep 23, 2026
Merged

maxekman merged 2 commits into
mainfrom
max/a2a-0-3-0

Conversation

@maxekman

Copy link
Copy Markdown
Contributor

Summary

Moves the optional A2A dependency to ~> 0.3.0. a2a 0.3.0 is that library's v1.0 protocol release; no A2UI code changed — the full suite passes against it as-is.

Type of change

  • Bug fix
  • New feature
  • Breaking change
  • Refactor / chore
  • Documentation

Why nothing broke

A2A 0.3 has three breaking changes: the StreamResponse wrapper on streaming events, google.rpc.ErrorInfo in error data, and message/stream gated on a declared capability.

A2UI touches none of them. lib/a2ui/transport/a2a.ex uses only A2A.Client.new, send_message and cancel_task; lib/a2ui/a2a.ex uses A2A.Part.Data. Zero references to streaming, StatusUpdate, ArtifactUpdate, kind or final in either file.

Verified:

Result
mix compile --warnings-as-errors clean
mix test 400 passed
mix bun test 49 passed
mix quality (format + credo + dialyzer) clean

Dialyzer passing matters here: A2A 0.3 widened send_message/3 to {:ok, Task.t() \| Message.t()}, and A2UI's specs absorb that without change.

Why ~> 0.3.0 and not ~> 0.3

~> 0.3 resolves to >= 0.3.0, < 1.0.0 — the same shape as the old ~> 0.2, which is exactly what let 0.3's wire changes land here unannounced. A2A is pre-1.0 and ships breaking changes in minor releases, so a range spanning minors is a standing surprise.

Pinning to one minor means each A2A bump is a deliberate PR like this one. The trade-off is a tighter resolution window for A2UI's own consumers, which is normally an argument against pinning in a library — but that argument assumes the dependency treats minors as safe, and A2A demonstrably doesn't yet.

This drops support for A2A 0.2.x, so it is a minor bump for A2UI rather than a patch.

Also pulled in

mix.lock picks up transitive updates, including mint 1.10.1 — which fixes EEF-CVE-2026-82672 (MEDIUM, HTTP/1 response smuggling), flagged by mix deps.get on 1.10.0.

A2A 0.3 is that library's v1.0 protocol release, and its breaking
changes are all in the streaming wire format, the error data shape and
the streaming capability gate. A2UI only ever uses the synchronous
path, so none of it reaches here — the full suite, dialyzer included,
passes against 0.3.0 with no code change.

The requirement now names a single A2A minor instead of the whole 0.x
range. A2A is pre-1.0 and ships breaking changes in minor releases, so
the old requirement let 0.3 land here unannounced and the obvious
replacement would do the same for 0.4. Supporting 0.2.x alongside is
not worth the compatibility surface now that 0.3 is out, so that
support is dropped rather than carried.
Stamps the changelog and installation snippet for release. Nothing
user-facing had landed since 0.2.0 in March beyond dependency bumps,
so this release is the configurable A2A sync timeout plus the move to
a2a 0.3.x — which drops a2a 0.2.x support, hence a minor rather than a
patch.

Also records the sync timeout in the changelog, which its own change
did not carry.
@maxekman

Copy link
Copy Markdown
Contributor Author

Rebased onto main with the other four PRs merged, conflict resolved, and extended to prepare the 0.3.0 release.

Conflict resolution

mix.lock conflicted against the merged dependency bumps. Rather than hand-merging the markers I reset the lock to main's and re-resolved it against the merged mix.exs, so every landed version is preserved and a2a is picked up on top:

a2a 0.3.0 (this PR)
phoenix_live_view 1.2.9 (#27)
bandit / ex_doc / dialyxir 1.12.5 / 0.40.4 / 1.4.8 (#35)
mint 1.10.1 — fixes EEF-CVE-2026-82672

Now also prepares 0.3.0

Two things needed fixing before this could be released:

  • The sync timeout from Configurable A2A sync timeout #33 had no changelog entry. Added one describing :a2a_sync_timeout, including that neither timeout is fatal — a synchronization that times out continues processing, and a drain that times out yields a response with no buffered A2UI parts.
  • SPEC.md still documented {:a2a, "~> 0.2"}. Updated alongside the requirement itself.

Plus the release stamp: @version "0.3.0", ## [0.3.0] - 2026-09-23, and the README install snippet to {:a2ui, "~> 0.3.0"}.

Why 0.3.0 and not 0.2.1: pinning to ~> 0.3.0 drops support for a2a 0.2.x, which is a dependency-contract break — a minor bump pre-1.0.

Verified after rebase

Result
mix compile --warnings-as-errors clean
mix test 400 passed
mix bun test 49 passed
mix quality (format + credo + dialyzer) clean

Two commits: the dependency requirement, then the release stamp.

Ready to tag v0.3.0 once merged.

@maxekman
maxekman merged commit 1150412 into main Sep 23, 2026
7 checks passed
@maxekman
maxekman deleted the max/a2a-0-3-0 branch September 23, 2026 09:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant