chroxy

Build log

nerves_system_bbb

chroxy 0.7.0 · fail · run chroxy-0.7.0-1790964236852
437 of 437 lines
1Resolving Hex dependencies...2Resolution completed in 0.27s3Unchanged:4  certifi 2.15.05  chrome_remote_interface 0.3.06  chroxy 0.7.07  circular_buffer 1.1.08  cowboy 2.8.0 VULNERABLE!9    GHSA-w4f7-4cxr-rv3c (MEDIUM)10    aka: CVE-2026-43966, EEF-CVE-2026-4396611    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability12    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c1314    EEF-CVE-2026-8466 (HIGH)15    aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x816    Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy17    https://osv.dev/vulnerability/EEF-CVE-2026-84661819    EEF-CVE-2026-65624 (MEDIUM)20    aka: CVE-2026-6562421    Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion22    https://osv.dev/vulnerability/EEF-CVE-2026-6562423  cowboy_telemetry 0.3.124  cowlib 2.9.1 VULNERABLE!25    EEF-CVE-2026-7790 (HIGH)26    aka: CVE-2026-7790, GHSA-32p9-57cr-4x6527    Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS28    https://osv.dev/vulnerability/EEF-CVE-2026-77902930    EEF-CVE-2026-43968 (MEDIUM)31    aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r32    CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/133    https://osv.dev/vulnerability/EEF-CVE-2026-439683435    EEF-CVE-2026-43970 (HIGH)36    aka: CVE-2026-43970, GHSA-84f2-rp86-235p37    Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame38    https://osv.dev/vulnerability/EEF-CVE-2026-439703940    EEF-CVE-2026-59248 (HIGH)41    aka: CVE-2026-5924842    Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS43    https://osv.dev/vulnerability/EEF-CVE-2026-592484445    EEF-CVE-2026-43969 (LOW)46    aka: CVE-2026-43969, GHSA-g2wm-735q-3f5647    Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/148    https://osv.dev/vulnerability/EEF-CVE-2026-439694950    EEF-CVE-2026-43966 (MEDIUM)51    aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c52    HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/253    https://osv.dev/vulnerability/EEF-CVE-2026-439665455    EEF-CVE-2026-43971 (MEDIUM)56    aka: CVE-2026-4397157    Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/158    https://osv.dev/vulnerability/EEF-CVE-2026-4397159  elixir_make 0.10.060  erlexec 1.10.9 RETIRED!61    (deprecated) Deprecated62  exexec 0.2.063  hackney 1.25.0 VULNERABLE!64    EEF-CVE-2026-47071 (HIGH)65    aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr66    SOCKS5 TLS upgrade ignores caller timeout in hackney67    https://osv.dev/vulnerability/EEF-CVE-2026-470716869    EEF-CVE-2026-47076 (MEDIUM)70    aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq71    SSRF allowlist bypass via percent-encoded host in hackney72    https://osv.dev/vulnerability/EEF-CVE-2026-470767374    EEF-CVE-2026-47069 (LOW)75    aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw276    CRLF injection in cookie domain/path options in hackney77    https://osv.dev/vulnerability/EEF-CVE-2026-470697879    EEF-CVE-2026-47075 (MEDIUM)80    aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf81    CR/LF injection in query parameter in hackney82    https://osv.dev/vulnerability/EEF-CVE-2026-4707583  idna 6.1.184  interactive_cmd 0.1.485  jason 1.4.586  metrics 1.0.187  mime 1.6.088  mimerl 1.5.089  nerves 2.0.0-pre.290  nerves_discovery 0.1.591  nerves_logging 0.2.492  nerves_runtime 0.13.1393  nerves_system_bbb 2.30.294  nerves_system_br 1.34.495  nerves_system_mangopi_mq_pro 0.17.296  nerves_system_qemu_aarch64 0.4.297  nerves_system_rpi0 2.1.298  nerves_system_rpi4 2.1.299  nerves_system_rpi5 2.1.2100  nerves_system_trellis 0.5.0101  nerves_system_x86_64 1.34.2102  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1103  nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1104  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1105  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1106  nerves_toolchain_x86_64_nerves_linux_musl 15.3.1107  nerves_uevent 0.1.7108  parse_trans 3.4.1109  plug 1.10.4 VULNERABLE!110    EEF-CVE-2026-8468 (HIGH)111    aka: CVE-2026-8468, GHSA-468c-vq7p-gh64112    Unbounded buffer accumulation in multipart header parsing causes denial of service in plug113    https://osv.dev/vulnerability/EEF-CVE-2026-8468114115    EEF-CVE-2026-56813 (LOW)116    aka: CVE-2026-56813, GHSA-wpmj-jh88-rpgm117    Cookie attribute injection in Plug.Conn.Cookies.encode/2118    https://osv.dev/vulnerability/EEF-CVE-2026-56813119120    EEF-CVE-2026-56814 (MEDIUM)121    aka: CVE-2026-56814, GHSA-95qv-c9g9-rm63122    Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)123    https://osv.dev/vulnerability/EEF-CVE-2026-56814124  plug_cowboy 2.4.1 VULNERABLE!125    EEF-CVE-2026-32688 (HIGH)126    aka: CVE-2026-32688, GHSA-q8x4-x7mp-5vg2127    Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy128    https://osv.dev/vulnerability/EEF-CVE-2026-32688129  plug_crypto 1.2.5130  poison 3.1.0131  property_table 0.3.4132  ranch 1.7.1133  ring_logger 0.11.7134  ssl_verify_fun 1.1.7135  tablet 0.3.3136  telemetry 0.4.3137  toolshed 0.5.0138  uboot_env 1.0.2139  unicode_util_compat 0.7.1140  websockex 0.4.3141* Getting chroxy (Hex package)142* Getting nerves (Hex package)143* Getting ring_logger (Hex package)144* Getting toolshed (Hex package)145* Getting nerves_runtime (Hex package)146* Getting nerves_system_bbb (Hex package)147* Getting nerves_system_mangopi_mq_pro (Hex package)148* Getting nerves_system_qemu_aarch64 (Hex package)149* Getting nerves_system_rpi0 (Hex package)150* Getting nerves_system_rpi4 (Hex package)151* Getting nerves_system_rpi5 (Hex package)152* Getting nerves_system_trellis (Hex package)153* Getting nerves_system_x86_64 (Hex package)154* Getting nerves_system_br (Hex package)155* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)156* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)157* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)158* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)159* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)160* Getting nerves_logging (Hex package)161* Getting nerves_uevent (Hex package)162* Getting uboot_env (Hex package)163* Getting elixir_make (Hex package)164* Getting property_table (Hex package)165* Getting circular_buffer (Hex package)166* Getting interactive_cmd (Hex package)167* Getting nerves_discovery (Hex package)168* Getting tablet (Hex package)169* Getting chrome_remote_interface (Hex package)170* Getting cowboy (Hex package)171* Getting erlexec (Hex package)172* Getting exexec (Hex package)173* Getting jason (Hex package)174* Getting plug (Hex package)175* Getting plug_cowboy (Hex package)176* Getting cowboy_telemetry (Hex package)177* Getting telemetry (Hex package)178* Getting mime (Hex package)179* Getting plug_crypto (Hex package)180* Getting cowlib (Hex package)181* Getting ranch (Hex package)182* Getting hackney (Hex package)183* Getting poison (Hex package)184* Getting websockex (Hex package)185* Getting certifi (Hex package)186* Getting idna (Hex package)187* Getting metrics (Hex package)188* Getting mimerl (Hex package)189* Getting parse_trans (Hex package)190* Getting ssl_verify_fun (Hex package)191* Getting unicode_util_compat (Hex package)192Found retired packages, see above for details193Found packages with security advisories, see above for details194    warning: String.strip/1 is deprecated. Use String.trim/1 instead195    │196  4 │   @version File.read!("VERSION") |> String.strip197    │                                            ~198    │199    └─ /work/proj/deps_bbb/poison/mix.exs:4:44: Poison.Mixfile (module)200201    warning: using single-quoted strings to represent charlists is deprecated.202    Use ~c"" if you indeed want a charlist or use "" instead.203    You may run "mix format --migrate" to change all single-quoted204    strings to use the ~c sigil and fix this warning.205    │206 21 │   defp elixirc_paths(:test), do: ['lib', 'test/support']207    │                                   ~208    │209    └─ /work/proj/deps_bbb/websockex/mix.exs:21:35210211    warning: using single-quoted strings to represent charlists is deprecated.212    Use ~c"" if you indeed want a charlist or use "" instead.213    You may run "mix format --migrate" to change all single-quoted214    strings to use the ~c sigil and fix this warning.215    │216 21 │   defp elixirc_paths(:test), do: ['lib', 'test/support']217    │                                          ~218    │219    └─ /work/proj/deps_bbb/websockex/mix.exs:21:42220221    warning: using single-quoted strings to represent charlists is deprecated.222    Use ~c"" if you indeed want a charlist or use "" instead.223    You may run "mix format --migrate" to change all single-quoted224    strings to use the ~c sigil and fix this warning.225    │226 22 │   defp elixirc_paths(_), do: ['lib']227    │                               ~228    │229    └─ /work/proj/deps_bbb/websockex/mix.exs:22:31230231==> nerves_system_br232Generated nerves_system_br app233==> mime234Compiling 2 files (.ex)235Generated mime app236==> circular_buffer237Compiling 1 file (.ex)238Generated circular_buffer app239==> jason240Compiling 10 files (.ex)241Generated jason app242==> poison243Compiling 4 files (.ex)244    warning: using single-quoted strings to represent charlists is deprecated.245    Use ~c"" if you indeed want a charlist or use "" instead.246    You may run "mix format --migrate" to change all single-quoted247    strings to use the ~c sigil and fix this warning.248    │249 93 │   for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do250    │                               ~251    │252    └─ lib/poison/encoder.ex:93:31253254    warning: using single-quoted strings to represent charlists is deprecated.255    Use ~c"" if you indeed want a charlist or use "" instead.256    You may run "mix format --migrate" to change all single-quoted257    strings to use the ~c sigil and fix this warning.258    │259 93 │   for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do260    │                                                ~261    │262    └─ lib/poison/encoder.ex:93:48263264     warning: using single-quoted strings to represent charlists is deprecated.265     Use ~c"" if you indeed want a charlist or use "" instead.266     You may run "mix format --migrate" to change all single-quoted267     strings to use the ~c sigil and fix this warning.268     │269 139 │   defp chunk_size(<<char>> <> _, _mode, acc) when char <= 0x1F or char in '"\\' do270     │                                                                           ~271     │272     └─ lib/poison/encoder.ex:139:75273274    warning: using single-quoted strings to represent charlists is deprecated.275    Use ~c"" if you indeed want a charlist or use "" instead.276    You may run "mix format --migrate" to change all single-quoted277    strings to use the ~c sigil and fix this warning.278    │279 77 │   defp value(<<char, _ :: binary>> = string, pos, _keys) when char in '-0123456789' do280    │                                                                       ~281    │282    └─ lib/poison/parser.ex:77:71283284     warning: using single-quoted strings to represent charlists is deprecated.285     Use ~c"" if you indeed want a charlist or use "" instead.286     You may run "mix format --migrate" to change all single-quoted287     strings to use the ~c sigil and fix this warning.288     │289 155 │   defp number_int(<<char, _ :: binary>> = string, pos, acc) when char in '123456789' do290     │                                                                          ~291     │292     └─ lib/poison/parser.ex:155:74293294     warning: using single-quoted strings to represent charlists is deprecated.295     Use ~c"" if you indeed want a charlist or use "" instead.296     You may run "mix format --migrate" to change all single-quoted297     strings to use the ~c sigil and fix this warning.298     │299 171 │   defp number_exp(<<e>> <> rest, frac, pos, acc) when e in 'eE' do300     │                                                            ~301     │302     └─ lib/poison/parser.ex:171:60303304     warning: using single-quoted strings to represent charlists is deprecated.305     Use ~c"" if you indeed want a charlist or use "" instead.306     You may run "mix format --migrate" to change all single-quoted307     strings to use the ~c sigil and fix this warning.308     │309 197 │   defp number_digits(<<char>> <> rest = string, pos) when char in '0123456789' do310     │                                                                   ~311     │312     └─ lib/poison/parser.ex:197:67313314     warning: using single-quoted strings to represent charlists is deprecated.315     Use ~c"" if you indeed want a charlist or use "" instead.316     You may run "mix format --migrate" to change all single-quoted317     strings to use the ~c sigil and fix this warning.318     │319 205 │   defp number_digits_count(<<char>> <> rest, acc) when char in '0123456789' do320     │                                                                ~321     │322     └─ lib/poison/parser.ex:205:64323324     warning: using single-quoted strings to represent charlists is deprecated.325     Use ~c"" if you indeed want a charlist or use "" instead.326     You may run "mix format --migrate" to change all single-quoted327     strings to use the ~c sigil and fix this warning.328     │329 229 │   for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do330     │                               ~331     │332     └─ lib/poison/parser.ex:229:31333334     warning: using single-quoted strings to represent charlists is deprecated.335     Use ~c"" if you indeed want a charlist or use "" instead.336     You may run "mix format --migrate" to change all single-quoted337     strings to use the ~c sigil and fix this warning.338     │339 229 │   for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do340     │                                            ~341     │342     └─ lib/poison/parser.ex:229:44343344     warning: using single-quoted strings to represent charlists is deprecated.345     Use ~c"" if you indeed want a charlist or use "" instead.346     You may run "mix format --migrate" to change all single-quoted347     strings to use the ~c sigil and fix this warning.348     │349 239 │     when a1 in 'dD' and a2 in 'dD'350     │                ~351     │352     └─ lib/poison/parser.ex:239:16353354     warning: using single-quoted strings to represent charlists is deprecated.355     Use ~c"" if you indeed want a charlist or use "" instead.356     You may run "mix format --migrate" to change all single-quoted357     strings to use the ~c sigil and fix this warning.358     │359 239 │     when a1 in 'dD' and a2 in 'dD'360     │                               ~361     │362     └─ lib/poison/parser.ex:239:31363364     warning: using single-quoted strings to represent charlists is deprecated.365     Use ~c"" if you indeed want a charlist or use "" instead.366     You may run "mix format --migrate" to change all single-quoted367     strings to use the ~c sigil and fix this warning.368     │369 240 │     and (b1 in '89abAB')370     │                ~371     │372     └─ lib/poison/parser.ex:240:16373374     warning: using single-quoted strings to represent charlists is deprecated.375     Use ~c"" if you indeed want a charlist or use "" instead.376     You may run "mix format --migrate" to change all single-quoted377     strings to use the ~c sigil and fix this warning.378     │379 274 │   defp skip_whitespace(<<char>> <> rest, pos) when char in '\s\n\t\r' do380     │                                                            ~381     │382     └─ lib/poison/parser.ex:274:60383384    warning: Application.get_env/2 is discouraged in the module body, use Application.compile_env/3 instead385    │386 22 │   if Application.get_env(:poison, :native) do387    │                  ~388    │389    └─ lib/poison/parser.ex:22:18: Poison.Parser (module)390391    warning: use Bitwise is deprecated. import Bitwise instead392    │393 26 │   use Bitwise394    │   ~~~~~~~~~~~395    │396    └─ lib/poison/parser.ex:26: Poison.Parser (module)397398     warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator399     │400 199 │     <<digits :: binary-size(count), rest :: binary>> = string401     │                             ~402     │403     └─ lib/poison/parser.ex:199:29: Poison.Parser.number_digits/2404405     warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator406     │407 225 │     <<chunk :: binary-size(count), rest :: binary>> = string408     │                            ~409     │410     └─ lib/poison/parser.ex:225:28: Poison.Parser.string_continue/3411412    warning: use Bitwise is deprecated. import Bitwise instead413    │414 83 │   use Bitwise415    │   ~~~~~~~~~~~416    │417    └─ lib/poison/encoder.ex:83: Poison.Encoder.BitString (module)418419     warning: the variable "size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator420     │421 135 │     <<chunk :: binary-size(size), rest :: binary>> = string422     │                            ~423     │424     └─ lib/poison/encoder.ex:135:28: Poison.Encoder.BitString.escape/2425426     warning: Integer.to_char_list/2 is deprecated. Use Integer.to_charlist/2 instead427     │428 173 │     case Integer.to_char_list(char, 16) do429     │                  ~430     │431     └─ lib/poison/encoder.ex:173:18: Poison.Encoder.BitString.seq/1432433Generated poison app434==> websockex435could not compile dependency :websockex, "mix compile" failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile websockex --force", update it with "mix deps.update websockex" or clean it with "mix deps.clean websockex"436==> nerves_compatibility_test437** (Mix) :elixirc_paths should be a list of string paths, got: [~c"lib"]