Build log
nerves_system_x86_64
allowed_hosts 0.1.2 · fail · run allowed_hosts-0.1.2-1789676894895
584 of 584 lines
1Resolving Hex dependencies...2Resolution completed in 0.46s3Unchanged:4 allowed_hosts 0.1.25 circular_buffer 1.1.06 cowboy 2.19.07 cowlib 2.20.0 VULNERABLE!8 EEF-CVE-2026-43966 (MEDIUM)9 aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c10 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/211 https://osv.dev/vulnerability/EEF-CVE-2026-439661213 EEF-CVE-2026-43969 (LOW)14 aka: CVE-2026-43969, GHSA-g2wm-735q-3f5615 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/116 https://osv.dev/vulnerability/EEF-CVE-2026-4396917 elixir_make 0.10.018 interactive_cmd 0.1.419 jason 1.4.520 mime 1.6.021 nerves 1.15.022 nerves_discovery 0.1.523 nerves_logging 0.2.424 nerves_runtime 0.13.1325 nerves_system_bbb 2.30.226 nerves_system_br 1.34.427 nerves_system_mangopi_mq_pro 0.17.228 nerves_system_qemu_aarch64 0.4.229 nerves_system_rpi 2.1.230 nerves_system_rpi0 2.1.231 nerves_system_rpi0_2 2.1.232 nerves_system_rpi2 2.1.233 nerves_system_rpi3 2.1.234 nerves_system_rpi4 2.1.235 nerves_system_rpi5 2.1.236 nerves_system_x86_64 1.34.237 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.138 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.139 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.140 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.141 nerves_toolchain_x86_64_nerves_linux_musl 15.3.142 nerves_uevent 0.1.743 plug 1.8.3 VULNERABLE!44 EEF-CVE-2026-8468 (HIGH)45 aka: CVE-2026-8468, GHSA-468c-vq7p-gh6446 Unbounded buffer accumulation in multipart header parsing causes denial of service in plug47 https://osv.dev/vulnerability/EEF-CVE-2026-84684849 EEF-CVE-2026-56814 (MEDIUM)50 aka: CVE-2026-56814, GHSA-95qv-c9g9-rm6351 Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)52 https://osv.dev/vulnerability/EEF-CVE-2026-568145354 EEF-CVE-2026-56813 (LOW)55 aka: CVE-2026-56813, GHSA-wpmj-jh88-rpgm56 Cookie attribute injection in Plug.Conn.Cookies.encode/257 https://osv.dev/vulnerability/EEF-CVE-2026-5681358 plug_crypto 1.2.559 property_table 0.3.460 ranch 2.3.061 ring_logger 0.11.762 shoehorn 0.9.363 tablet 0.3.364 toolshed 0.5.065 uboot_env 1.0.266* Getting allowed_hosts (Hex package)67* Getting nerves (Hex package)68* Getting shoehorn (Hex package)69* Getting ring_logger (Hex package)70* Getting toolshed (Hex package)71* Getting nerves_runtime (Hex package)72* Getting nerves_system_bbb (Hex package)73* Getting nerves_system_mangopi_mq_pro (Hex package)74* Getting nerves_system_qemu_aarch64 (Hex package)75* Getting nerves_system_rpi (Hex package)76* Getting nerves_system_rpi0 (Hex package)77* Getting nerves_system_rpi0_2 (Hex package)78* Getting nerves_system_rpi2 (Hex package)79* Getting nerves_system_rpi3 (Hex package)80* Getting nerves_system_rpi4 (Hex package)81* Getting nerves_system_rpi5 (Hex package)82* Getting nerves_system_x86_64 (Hex package)83* Getting nerves_system_br (Hex package)84* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)85* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)86* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)87* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)88* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)89* Getting nerves_logging (Hex package)90* Getting nerves_uevent (Hex package)91* Getting uboot_env (Hex package)92* Getting elixir_make (Hex package)93* Getting property_table (Hex package)94* Getting circular_buffer (Hex package)95* Getting interactive_cmd (Hex package)96* Getting jason (Hex package)97* Getting nerves_discovery (Hex package)98* Getting tablet (Hex package)99* Getting cowboy (Hex package)100* Getting plug (Hex package)101* Getting mime (Hex package)102* Getting plug_crypto (Hex package)103* Getting cowlib (Hex package)104* Getting ranch (Hex package)105Found packages with security advisories, see above for details106You have added/upgraded packages you could sponsor, run `mix hex.sponsor` to learn more107==> jason108Compiling 10 files (.ex)109Compiling lib/encode.ex (it's taking more than 10s)110Compiling lib/decoder.ex (it's taking more than 10s)111Generated jason app112==> tablet113Compiling 2 files (.ex)114Generated tablet app115==> elixir_make116Compiling 8 files (.ex)117Generated elixir_make app118==> nerves_discovery119Compiling 5 files (.ex)120Generated nerves_discovery app121==> interactive_cmd122Compiling 1 file (.ex)123Generated interactive_cmd app124==> nerves125HOST_CC port.o126HOST_LD port127Compiling 55 files (.ex)128Generated nerves app129==> nerves_compatibility_test130131Nerves environment132 MIX_TARGET: x86_64133 MIX_ENV: prod134135Checking for prebuilt Nerves artifacts...136 Found nerves_system_x86_64 in cache137 /home/nerves/.nerves/artifacts/nerves_system_x86_64-portable-1.34.2138 Found nerves_toolchain_x86_64_nerves_linux_musl in cache139 /home/nerves/.nerves/artifacts/nerves_toolchain_x86_64_nerves_linux_musl-linux_x86_64-15.3.1140==> nerves141==> nerves_compatibility_test142143Nerves environment144 MIX_TARGET: x86_64145 MIX_ENV: prod146147==> plug148Compiling 1 file (.erl)149warning: "xref: [exclude: ...]" in your mix.exs file is deprecated, instead use: "elixirc_options: [no_warn_undefined: ...]"150 (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:243: Mix.Tasks.Compile.Elixir.xref_exclude_opts/2151 (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:142: Mix.Tasks.Compile.Elixir.run/1152 (mix 1.20.3) lib/mix/task.ex:502: anonymous fn/3 in Mix.Task.run_task/5153 (mix 1.20.3) lib/mix/task.compiler.ex:299: Mix.Task.Compiler.run_compiler/2154 (mix 1.20.3) lib/mix/task.compiler.ex:287: Mix.Task.Compiler.run/4155 (mix 1.20.3) lib/mix/tasks/compile.all.ex:75: Mix.Tasks.Compile.All.do_run/2156157Compiling 39 files (.ex)158 warning: using single-quoted strings to represent charlists is deprecated.159 Use ~c"" if you indeed want a charlist or use "" instead.160 You may run "mix format --migrate" to change all single-quoted161 strings to use the ~c sigil and fix this warning.162 │163 352 │ generated? = :erlang.system_info(:otp_release) >= '19'164 │ ~165 │166 └─ lib/plug/builder.ex:352:55167168 warning: Application.get_env/3 is discouraged in the module body, use Application.compile_env/3 instead169 │170 6 │ custom_statuses = Application.get_env(:plug, :statuses, %{})171 │ ~172 │173 └─ lib/plug/conn/status.ex:6:33: Plug.Conn.Status (module)174175 warning: unused require Bitwise176 │177 101 │ require Bitwise178 │ ~179 │180 └─ lib/plug/csrf_protection.ex:101:3181182 warning: Application.get_env/2 is discouraged in the module body, use Application.compile_env/3 instead183 │184 4 │ if Application.get_env(:plug, :mimes) do185 │ ~186 │187 └─ lib/plug/mime.ex:4:18: Plug.MIME (module)188189 warning: unused require Logger190 │191 34 │ require Logger192 │ ~193 │194 └─ lib/plug/request_id.ex:34:3195196 warning: using single-quoted strings to represent charlists is deprecated.197 Use ~c"" if you indeed want a charlist or use "" instead.198 You may run "mix format --migrate" to change all single-quoted199 strings to use the ~c sigil and fix this warning.200 │201 65 │ 'ECDHE-RSA-AES256-GCM-SHA384',202 │ ~203 │204 └─ lib/plug/ssl.ex:65:5205206 warning: using single-quoted strings to represent charlists is deprecated.207 Use ~c"" if you indeed want a charlist or use "" instead.208 You may run "mix format --migrate" to change all single-quoted209 strings to use the ~c sigil and fix this warning.210 │211 66 │ 'ECDHE-ECDSA-AES256-GCM-SHA384',212 │ ~213 │214 └─ lib/plug/ssl.ex:66:5215216 warning: using single-quoted strings to represent charlists is deprecated.217 Use ~c"" if you indeed want a charlist or use "" instead.218 You may run "mix format --migrate" to change all single-quoted219 strings to use the ~c sigil and fix this warning.220 │221 67 │ 'ECDHE-RSA-AES128-GCM-SHA256',222 │ ~223 │224 └─ lib/plug/ssl.ex:67:5225226 warning: using single-quoted strings to represent charlists is deprecated.227 Use ~c"" if you indeed want a charlist or use "" instead.228 You may run "mix format --migrate" to change all single-quoted229 strings to use the ~c sigil and fix this warning.230 │231 68 │ 'ECDHE-ECDSA-AES128-GCM-SHA256',232 │ ~233 │234 └─ lib/plug/ssl.ex:68:5235236 warning: using single-quoted strings to represent charlists is deprecated.237 Use ~c"" if you indeed want a charlist or use "" instead.238 You may run "mix format --migrate" to change all single-quoted239 strings to use the ~c sigil and fix this warning.240 │241 69 │ 'DHE-RSA-AES256-GCM-SHA384',242 │ ~243 │244 └─ lib/plug/ssl.ex:69:5245246 warning: using single-quoted strings to represent charlists is deprecated.247 Use ~c"" if you indeed want a charlist or use "" instead.248 You may run "mix format --migrate" to change all single-quoted249 strings to use the ~c sigil and fix this warning.250 │251 70 │ 'DHE-RSA-AES128-GCM-SHA256'252 │ ~253 │254 └─ lib/plug/ssl.ex:70:5255256 warning: using single-quoted strings to represent charlists is deprecated.257 Use ~c"" if you indeed want a charlist or use "" instead.258 You may run "mix format --migrate" to change all single-quoted259 strings to use the ~c sigil and fix this warning.260 │261 74 │ 'ECDHE-RSA-AES256-GCM-SHA384',262 │ ~263 │264 └─ lib/plug/ssl.ex:74:5265266 warning: using single-quoted strings to represent charlists is deprecated.267 Use ~c"" if you indeed want a charlist or use "" instead.268 You may run "mix format --migrate" to change all single-quoted269 strings to use the ~c sigil and fix this warning.270 │271 75 │ 'ECDHE-ECDSA-AES256-GCM-SHA384',272 │ ~273 │274 └─ lib/plug/ssl.ex:75:5275276 warning: using single-quoted strings to represent charlists is deprecated.277 Use ~c"" if you indeed want a charlist or use "" instead.278 You may run "mix format --migrate" to change all single-quoted279 strings to use the ~c sigil and fix this warning.280 │281 76 │ 'ECDHE-RSA-AES128-GCM-SHA256',282 │ ~283 │284 └─ lib/plug/ssl.ex:76:5285286 warning: using single-quoted strings to represent charlists is deprecated.287 Use ~c"" if you indeed want a charlist or use "" instead.288 You may run "mix format --migrate" to change all single-quoted289 strings to use the ~c sigil and fix this warning.290 │291 77 │ 'ECDHE-ECDSA-AES128-GCM-SHA256',292 │ ~293 │294 └─ lib/plug/ssl.ex:77:5295296 warning: using single-quoted strings to represent charlists is deprecated.297 Use ~c"" if you indeed want a charlist or use "" instead.298 You may run "mix format --migrate" to change all single-quoted299 strings to use the ~c sigil and fix this warning.300 │301 78 │ 'DHE-RSA-AES256-GCM-SHA384',302 │ ~303 │304 └─ lib/plug/ssl.ex:78:5305306 warning: using single-quoted strings to represent charlists is deprecated.307 Use ~c"" if you indeed want a charlist or use "" instead.308 You may run "mix format --migrate" to change all single-quoted309 strings to use the ~c sigil and fix this warning.310 │311 79 │ 'DHE-RSA-AES128-GCM-SHA256',312 │ ~313 │314 └─ lib/plug/ssl.ex:79:5315316 warning: using single-quoted strings to represent charlists is deprecated.317 Use ~c"" if you indeed want a charlist or use "" instead.318 You may run "mix format --migrate" to change all single-quoted319 strings to use the ~c sigil and fix this warning.320 │321 80 │ 'ECDHE-RSA-AES256-SHA384',322 │ ~323 │324 └─ lib/plug/ssl.ex:80:5325326 warning: using single-quoted strings to represent charlists is deprecated.327 Use ~c"" if you indeed want a charlist or use "" instead.328 You may run "mix format --migrate" to change all single-quoted329 strings to use the ~c sigil and fix this warning.330 │331 81 │ 'ECDHE-ECDSA-AES256-SHA384',332 │ ~333 │334 └─ lib/plug/ssl.ex:81:5335336 warning: using single-quoted strings to represent charlists is deprecated.337 Use ~c"" if you indeed want a charlist or use "" instead.338 You may run "mix format --migrate" to change all single-quoted339 strings to use the ~c sigil and fix this warning.340 │341 82 │ 'ECDHE-RSA-AES128-SHA256',342 │ ~343 │344 └─ lib/plug/ssl.ex:82:5345346 warning: using single-quoted strings to represent charlists is deprecated.347 Use ~c"" if you indeed want a charlist or use "" instead.348 You may run "mix format --migrate" to change all single-quoted349 strings to use the ~c sigil and fix this warning.350 │351 83 │ 'ECDHE-ECDSA-AES128-SHA256',352 │ ~353 │354 └─ lib/plug/ssl.ex:83:5355356 warning: using single-quoted strings to represent charlists is deprecated.357 Use ~c"" if you indeed want a charlist or use "" instead.358 You may run "mix format --migrate" to change all single-quoted359 strings to use the ~c sigil and fix this warning.360 │361 84 │ 'DHE-RSA-AES256-SHA256',362 │ ~363 │364 └─ lib/plug/ssl.ex:84:5365366 warning: using single-quoted strings to represent charlists is deprecated.367 Use ~c"" if you indeed want a charlist or use "" instead.368 You may run "mix format --migrate" to change all single-quoted369 strings to use the ~c sigil and fix this warning.370 │371 85 │ 'DHE-RSA-AES128-SHA256',372 │ ~373 │374 └─ lib/plug/ssl.ex:85:5375376 warning: using single-quoted strings to represent charlists is deprecated.377 Use ~c"" if you indeed want a charlist or use "" instead.378 You may run "mix format --migrate" to change all single-quoted379 strings to use the ~c sigil and fix this warning.380 │381 86 │ 'ECDHE-RSA-AES256-SHA',382 │ ~383 │384 └─ lib/plug/ssl.ex:86:5385386 warning: using single-quoted strings to represent charlists is deprecated.387 Use ~c"" if you indeed want a charlist or use "" instead.388 You may run "mix format --migrate" to change all single-quoted389 strings to use the ~c sigil and fix this warning.390 │391 87 │ 'ECDHE-ECDSA-AES256-SHA',392 │ ~393 │394 └─ lib/plug/ssl.ex:87:5395396 warning: using single-quoted strings to represent charlists is deprecated.397 Use ~c"" if you indeed want a charlist or use "" instead.398 You may run "mix format --migrate" to change all single-quoted399 strings to use the ~c sigil and fix this warning.400 │401 88 │ 'ECDHE-RSA-AES128-SHA',402 │ ~403 │404 └─ lib/plug/ssl.ex:88:5405406 warning: using single-quoted strings to represent charlists is deprecated.407 Use ~c"" if you indeed want a charlist or use "" instead.408 You may run "mix format --migrate" to change all single-quoted409 strings to use the ~c sigil and fix this warning.410 │411 89 │ 'ECDHE-ECDSA-AES128-SHA'412 │ ~413 │414 └─ lib/plug/ssl.ex:89:5415416 warning: System.stacktrace/0 is deprecated. Use __STACKTRACE__ instead417 │418 45 │ reraise e, System.stacktrace()419 │ ~420 │421 └─ lib/plug/parsers/multipart.ex:45:27: Plug.Parsers.MULTIPART.parse/5422 └─ lib/plug/parsers/multipart.ex:49:73: Plug.Parsers.MULTIPART.parse/5423424 warning: the following clause will never match:425426 {:error, reason} ->427428 because it attempts to match on the result of:429430 IO.binwrite(device, contents)431432 which has type:433434 dynamic(not {:error, term()})435436 type warning found at:437 │438 171 │ {:error, reason} ->439 │ ~~~~~~~~~~~~~~~~~~~440 │441 └─ lib/plug/parsers/multipart.ex:171: Plug.Parsers.MULTIPART.binwrite!/2442443 warning: Supervisor.Spec.worker/2 is deprecated. Use the new child specifications outlined in the Supervisor module instead444 │445 12 │ worker(Plug.Upload, [])446 │ ~447 │448 └─ lib/plug/supervisor.ex:12:7: Plug.Supervisor.init/1449450 warning: Supervisor.Spec.supervise/2 is deprecated. Use the new child specifications outlined in the Supervisor module instead451 │452 16 │ supervise(children, strategy: :one_for_one)453 │ ~454 │455 └─ lib/plug/supervisor.ex:16:5: Plug.Supervisor.init/1456457 warning: Plug.Crypto.safe_binary_to_term/1 is deprecated. Use non_executable_binary_to_term/2458 │459 134 │ Plug.Crypto.safe_binary_to_term(binary)460 │ ~461 │462 └─ lib/plug/session/cookie.ex:134:20: Plug.Session.COOKIE.decode/3463464 warning: Macro.to_string/2 is deprecated. Use Macro.to_string/1 instead465 │466 360 │ "#{kind} " <> Macro.to_string(code, &clause_match/2)467 │ ~468 │469 └─ lib/plug/debugger.ex:360:31: Plug.Debugger.get_clauses/3470471 warning: Code.ensure_compiled?/1 is deprecated. Use Code.ensure_compiled/1 instead (see the proper disclaimers in its docs)472 │473 45 │ unless Code.ensure_compiled?(module) and function_exported?(module, fun, arity) do474 │ ~475 │476 └─ lib/plug/parsers/json.ex:45:17: Plug.Parsers.JSON.validate_decoder!/1477 └─ lib/plug/parsers/json.ex:53:17: Plug.Parsers.JSON.validate_decoder!/1478479 warning: Code.ensure_compiled?/1 is deprecated. Use Code.ensure_compiled/1 instead (see the proper disclaimers in its docs)480 │481 244 │ if Code.ensure_compiled?(module) and function_exported?(module, :init, 1) do482 │ ~483 │484 └─ lib/plug/parsers.ex:244:15: Plug.Parsers.convert_parsers/2485486 warning: MIME.valid?/1 is deprecated. Use MIME.extensions(type) != [] instead487 │488 32 │ MIME.valid?(type)489 │ ~490 │491 └─ lib/plug/mime.ex:32:10: Plug.MIME.valid?/1492493 warning: System.stacktrace/0 is deprecated. Use __STACKTRACE__ instead494 │495 23 │ reraise(conn, kind, reason, System.stacktrace())496 │ ~497 │498 └─ lib/plug/conn/wrapper_error.ex:23:40: Plug.Conn.WrapperError.reraise/3499500 warning: a struct for Plug.Conn is expected on struct update:501502 %Plug.Conn{503 conn504 | adapter: {Plug.Adapters.Test.Conn, state},505 host: uri.host || conn.host || "www.example.com",506 method: method,507 owner: owner,508 path_info: split_path(uri.path),509 port: uri.port || 80,510 remote_ip: conn.remote_ip || {127, 0, 0, 1},511 req_headers: req_headers,512 request_path: uri.path,513 query_string: query,514 body_params: body_params || %Plug.Conn.Unfetched{aspect: :body_params},515 params: params || %Plug.Conn.Unfetched{aspect: :params},516 scheme: String.to_atom(String.downcase(uri.scheme || "http"))517 }518519 but got type:520521 dynamic(%{..., adapter: {atom(), term()}, req_headers: term()})522523 where "conn" was given the types:524525 # type: dynamic(%{..., req_headers: term()})526 # from: lib/plug/adapters/test/conn.ex:16:7527 body_or_params(body_or_params, query, conn.req_headers)528529 # type: dynamic(%{..., adapter: {atom(), term()}, req_headers: term()})530 # from: lib/plug/adapters/test/conn.ex:25:22531 get_from_adapter(conn, :get_http_protocol, :"HTTP/1.1")532533 when defining the variable "conn", you must also pattern match on "%Plug.Conn{}"534535 type warning found at:536 │537 34 │ %Plug.Conn{538 │ ~539 │540 └─ lib/plug/adapters/test/conn.ex:34:5: Plug.Adapters.Test.Conn.conn/4541542Generated plug app543==> allowed_hosts544Compiling 1 file (.ex)545Generated allowed_hosts app546==> nerves_compatibility_test547Compiling 2 files (.ex)548Generated nerves_compatibility_test app549|nerves| Building OTP Release...550551* [Nerves] validating vm.args552* skipping runtime configuration (config/runtime.exs not found)553* creating _build/x86_64/rel/nerves_compatibility_test/releases/0.1.0/vm.args554Updating base firmware image with Erlang release...555Copying rootfs_overlay: /work/proj/_build/x86_64/nerves/rootfs_overlay556Copying rootfs_overlay: /work/proj/rootfs_overlay557Building /work/proj/_build/x86_64/nerves/images/nerves_compatibility_test.fw...558Firmware UUID: crucial-peasant (3ba99d19-ad3e-5f17-f1f6-4bd4c0cccf58)559Firmware built successfully! 🎉560561Now you may install it to a MicroSD card using `mix burn` or upload it562to a device with `mix upload` or `mix firmware.gen.script`+`./upload.sh`.563564==> nerves565==> nerves_compatibility_test566567Nerves environment568 MIX_TARGET: x86_64569 MIX_ENV: prod570571==> allowed_hosts572Compiling 1 file (.ex)573 error: module Plug.Conn is not loaded and could not be found574 │575 12 │ import Plug.Conn, only: [send_resp: 3, halt: 1]576 │ ^577 │578 └─ lib/allowed_hosts.ex:12:3: AllowedHosts (module)579580581== Compilation error in file lib/allowed_hosts.ex ==582** (CompileError) lib/allowed_hosts.ex: cannot compile module AllowedHosts (errors have been logged)583584could not compile dependency :allowed_hosts, "mix compile" failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile allowed_hosts --force", update it with "mix deps.update allowed_hosts" or clean it with "mix deps.clean allowed_hosts"