Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
51 changes: 51 additions & 0 deletions .audit_ignore
Original file line number Diff line number Diff line change
Expand Up @@ -58,3 +58,54 @@ EEF-CVE-2026-43966
# RETIRE the moment cowlib publishes a release that validates cookie/1, and
# move the lock to that release.
EEF-CVE-2026-43969

# mint advisories. Verified 2026-09-28 against the ERLEF CNA records that
# hex.audit serves (https://api.osv.dev/v1/vulns/<id>) and the mint 1.10.1 and
# 1.11.0 sources.
#
# Shared facts. mint 1.11.0 fixes all three, and mix.lock holds 1.10.1 anyway.
# mint 1.11.0 no longer closes an HTTP/1 connection on a receive timeout (the
# `{:error, %Mint.TransportError{reason: :timeout}}` clause of
# Mint.HTTP1.recv/3), and Finch 0.23.0, the newest release, returns any open
# connection to its pool (transfer_if_open in lib/finch/http1/pool.ex). The
# next request on that connection is written behind the unanswered one and
# times out, and so does a retry that lands there; if the server answers late,
# a later request on it raises CaseClauseError inside Finch. On 1.10.1 the
# retry opens a new connection. test/timed_out_connection_test.exs fails on
# 1.11.0 with Finch 0.23.0 and passes on 1.10.1. Req and ReqLLM speak HTTP/1
# unless a caller configures otherwise (Req's default protocols are [:http1];
# ReqLLM's @default_stream_pool_protocols is [:http1]), and Imp opens HTTP/2
# only when a caller asks, through the benchmark parity task's
# --req-llm-pool-protocols.
# RETIRE all three together when a Finch release closes a connection that
# still has a request in flight, such as one that includes
# https://github.com/sneako/finch/pull/397 ("Close abandoned HTTP/1
# connections after request errors", open and unreleased on 2026-09-28), or
# when a mint release closes the connection on a receive timeout again. Then
# move the lock to that Finch release and mint 1.11 in the same change, and
# the timed-out-connection test must still pass.

# EEF-CVE-2026-91043 / CVE-2026-91043 / GHSA-9x8p-qrf4-jq7g (HIGH) - HPACK
# indexed cookie fields in a Mint HTTP/2 response bypass max_header_list_size
# and exhaust client memory. HTTP/2 only (Mint.HTTP2): not reachable through
# Imp's HTTP/1 default. Reachable in an application that configures HTTP/2
# for Req or ReqLLM against a malicious server. Retire as above.
EEF-CVE-2026-91043

# EEF-CVE-2026-92103 / CVE-2026-92103 / GHSA-q95c-ccq6-j5j6 (MEDIUM) - the
# Mint HTTP/2 client buffers a frame up to 16 MiB before enforcing
# max_frame_size. HTTP/2 only (Mint.HTTP2.Frame): not reachable through Imp's
# HTTP/1 default. Retire as above.
EEF-CVE-2026-92103

# EEF-CVE-2026-94194 / CVE-2026-94194 / GHSA-gvrc-75rc-7gj9 (MEDIUM) - the
# Mint HTTP/1 client applies chunked framing when chunked is not the final
# transfer coding, and keeps an HTTP/1.0 connection open after a response with
# Transfer-Encoding. This one is HTTP/1 and is reachable: a malicious server
# behind an intermediary that follows RFC 9112 can desynchronize the
# intermediary and Mint on a pooled connection and poison the responses to
# later requests. It needs both the malicious server and such an intermediary
# between it and Imp. It is ignored because the fix comes only with mint
# 1.11.0, whose timeout behaviour breaks every HTTP/1 client of Finch 0.23.0,
# not because it is a false positive. Retire as above.
EEF-CVE-2026-94194
768 changes: 395 additions & 373 deletions CHANGELOG.md

Large diffs are not rendered by default.

9 changes: 4 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,7 +145,7 @@ text or JSON you can score, such as an agent's tool descriptions.
## Install

```elixir
{:imp, "~> 0.5"}
{:imp, "~> 0.6"}
```

Imp needs Elixir 1.19 or later and a C and C++ compiler, for the native code
Expand All @@ -154,16 +154,15 @@ access, because erlexec's build fetches rebar3 plugins. It reaches models throug
[ReqLLM](https://hex.pm/packages/req_llm), so any provider ReqLLM supports
works.

Imp 0.5 is experimental and is its first release on Hex. Its API may still
change, and its optimizers need large-scale benchmarking. Bug reports and
pull requests are welcome.
Imp 0.6 is experimental. Its API may still change, and its optimizers need
large-scale benchmarking. Bug reports and pull requests are welcome.

## Learn

- [Getting started](docs/getting-started/index.md) builds one program step by
step, from the first call to a supervised server, with real scores.
- [Coming from DSPy](docs/coming-from-dspy.md) maps DSPy's names to Imp's.
- [Tutorials](https://github.com/deepfates/imp/tree/v0.5.0/livebooks) are Livebook notebooks
- [Tutorials](https://github.com/deepfates/imp/tree/v0.6.0/livebooks) are Livebook notebooks
you can run offline or with a key.
- The [cheatsheet](docs/cheatsheet.cheatmd) has the common calls on one page.

Expand Down
Loading
Loading