build(deps): require a2a ~> 0.3.0 - #37
Conversation
A2A 0.3 is that library's v1.0 protocol release, and its breaking changes are all in the streaming wire format, the error data shape and the streaming capability gate. A2UI only ever uses the synchronous path, so none of it reaches here — the full suite, dialyzer included, passes against 0.3.0 with no code change. The requirement now names a single A2A minor instead of the whole 0.x range. A2A is pre-1.0 and ships breaking changes in minor releases, so the old requirement let 0.3 land here unannounced and the obvious replacement would do the same for 0.4. Supporting 0.2.x alongside is not worth the compatibility surface now that 0.3 is out, so that support is dropped rather than carried.
Stamps the changelog and installation snippet for release. Nothing user-facing had landed since 0.2.0 in March beyond dependency bumps, so this release is the configurable A2A sync timeout plus the move to a2a 0.3.x — which drops a2a 0.2.x support, hence a minor rather than a patch. Also records the sync timeout in the changelog, which its own change did not carry.
7b91e8b to
32d82b8
Compare
|
Rebased onto Conflict resolution
Now also prepares 0.3.0Two things needed fixing before this could be released:
Plus the release stamp: Why 0.3.0 and not 0.2.1: pinning to Verified after rebase
Two commits: the dependency requirement, then the release stamp. Ready to tag |
Summary
Moves the optional A2A dependency to
~> 0.3.0. a2a 0.3.0 is that library's v1.0 protocol release; no A2UI code changed — the full suite passes against it as-is.Type of change
Why nothing broke
A2A 0.3 has three breaking changes: the
StreamResponsewrapper on streaming events,google.rpc.ErrorInfoin error data, andmessage/streamgated on a declared capability.A2UI touches none of them.
lib/a2ui/transport/a2a.exuses onlyA2A.Client.new,send_messageandcancel_task;lib/a2ui/a2a.exusesA2A.Part.Data. Zero references to streaming,StatusUpdate,ArtifactUpdate,kindorfinalin either file.Verified:
mix compile --warnings-as-errorsmix testmix bun testmix quality(format + credo + dialyzer)Dialyzer passing matters here: A2A 0.3 widened
send_message/3to{:ok, Task.t() \| Message.t()}, and A2UI's specs absorb that without change.Why
~> 0.3.0and not~> 0.3~> 0.3resolves to>= 0.3.0, < 1.0.0— the same shape as the old~> 0.2, which is exactly what let 0.3's wire changes land here unannounced. A2A is pre-1.0 and ships breaking changes in minor releases, so a range spanning minors is a standing surprise.Pinning to one minor means each A2A bump is a deliberate PR like this one. The trade-off is a tighter resolution window for A2UI's own consumers, which is normally an argument against pinning in a library — but that argument assumes the dependency treats minors as safe, and A2A demonstrably doesn't yet.
This drops support for A2A 0.2.x, so it is a minor bump for A2UI rather than a patch.
Also pulled in
mix.lockpicks up transitive updates, including mint 1.10.1 — which fixes EEF-CVE-2026-82672 (MEDIUM, HTTP/1 response smuggling), flagged bymix deps.geton 1.10.0.