Build log
nerves_system_rpi0
chroxy 0.7.0 · fail · run chroxy-0.7.0-1790964236852
437 of 437 lines
1Resolving Hex dependencies...2Resolution completed in 0.227s3Unchanged:4 certifi 2.15.05 chrome_remote_interface 0.3.06 chroxy 0.7.07 circular_buffer 1.1.08 cowboy 2.8.0 VULNERABLE!9 GHSA-w4f7-4cxr-rv3c (MEDIUM)10 aka: CVE-2026-43966, EEF-CVE-2026-4396611 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability12 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c1314 EEF-CVE-2026-8466 (HIGH)15 aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x816 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy17 https://osv.dev/vulnerability/EEF-CVE-2026-84661819 EEF-CVE-2026-65624 (MEDIUM)20 aka: CVE-2026-6562421 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion22 https://osv.dev/vulnerability/EEF-CVE-2026-6562423 cowboy_telemetry 0.3.124 cowlib 2.9.1 VULNERABLE!25 EEF-CVE-2026-7790 (HIGH)26 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6527 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS28 https://osv.dev/vulnerability/EEF-CVE-2026-77902930 EEF-CVE-2026-43968 (MEDIUM)31 aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r32 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/133 https://osv.dev/vulnerability/EEF-CVE-2026-439683435 EEF-CVE-2026-43970 (HIGH)36 aka: CVE-2026-43970, GHSA-84f2-rp86-235p37 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame38 https://osv.dev/vulnerability/EEF-CVE-2026-439703940 EEF-CVE-2026-59248 (HIGH)41 aka: CVE-2026-5924842 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS43 https://osv.dev/vulnerability/EEF-CVE-2026-592484445 EEF-CVE-2026-43969 (LOW)46 aka: CVE-2026-43969, GHSA-g2wm-735q-3f5647 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/148 https://osv.dev/vulnerability/EEF-CVE-2026-439694950 EEF-CVE-2026-43966 (MEDIUM)51 aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c52 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/253 https://osv.dev/vulnerability/EEF-CVE-2026-439665455 EEF-CVE-2026-43971 (MEDIUM)56 aka: CVE-2026-4397157 Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/158 https://osv.dev/vulnerability/EEF-CVE-2026-4397159 elixir_make 0.10.060 erlexec 1.10.9 RETIRED!61 (deprecated) Deprecated62 exexec 0.2.063 hackney 1.25.0 VULNERABLE!64 EEF-CVE-2026-47071 (HIGH)65 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr66 SOCKS5 TLS upgrade ignores caller timeout in hackney67 https://osv.dev/vulnerability/EEF-CVE-2026-470716869 EEF-CVE-2026-47076 (MEDIUM)70 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq71 SSRF allowlist bypass via percent-encoded host in hackney72 https://osv.dev/vulnerability/EEF-CVE-2026-470767374 EEF-CVE-2026-47069 (LOW)75 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw276 CRLF injection in cookie domain/path options in hackney77 https://osv.dev/vulnerability/EEF-CVE-2026-470697879 EEF-CVE-2026-47075 (MEDIUM)80 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf81 CR/LF injection in query parameter in hackney82 https://osv.dev/vulnerability/EEF-CVE-2026-4707583 idna 6.1.184 interactive_cmd 0.1.485 jason 1.4.586 metrics 1.0.187 mime 1.6.088 mimerl 1.5.089 nerves 2.0.0-pre.290 nerves_discovery 0.1.591 nerves_logging 0.2.492 nerves_runtime 0.13.1393 nerves_system_bbb 2.30.294 nerves_system_br 1.34.495 nerves_system_mangopi_mq_pro 0.17.296 nerves_system_qemu_aarch64 0.4.297 nerves_system_rpi0 2.1.298 nerves_system_rpi4 2.1.299 nerves_system_rpi5 2.1.2100 nerves_system_trellis 0.5.0101 nerves_system_x86_64 1.34.2102 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1103 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1104 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1105 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1106 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1107 nerves_uevent 0.1.7108 parse_trans 3.4.1109 plug 1.10.4 VULNERABLE!110 EEF-CVE-2026-8468 (HIGH)111 aka: CVE-2026-8468, GHSA-468c-vq7p-gh64112 Unbounded buffer accumulation in multipart header parsing causes denial of service in plug113 https://osv.dev/vulnerability/EEF-CVE-2026-8468114115 EEF-CVE-2026-56813 (LOW)116 aka: CVE-2026-56813, GHSA-wpmj-jh88-rpgm117 Cookie attribute injection in Plug.Conn.Cookies.encode/2118 https://osv.dev/vulnerability/EEF-CVE-2026-56813119120 EEF-CVE-2026-56814 (MEDIUM)121 aka: CVE-2026-56814, GHSA-95qv-c9g9-rm63122 Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)123 https://osv.dev/vulnerability/EEF-CVE-2026-56814124 plug_cowboy 2.4.1 VULNERABLE!125 EEF-CVE-2026-32688 (HIGH)126 aka: CVE-2026-32688, GHSA-q8x4-x7mp-5vg2127 Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy128 https://osv.dev/vulnerability/EEF-CVE-2026-32688129 plug_crypto 1.2.5130 poison 3.1.0131 property_table 0.3.4132 ranch 1.7.1133 ring_logger 0.11.7134 ssl_verify_fun 1.1.7135 tablet 0.3.3136 telemetry 0.4.3137 toolshed 0.5.0138 uboot_env 1.0.2139 unicode_util_compat 0.7.1140 websockex 0.4.3141* Getting chroxy (Hex package)142* Getting nerves (Hex package)143* Getting ring_logger (Hex package)144* Getting toolshed (Hex package)145* Getting nerves_runtime (Hex package)146* Getting nerves_system_bbb (Hex package)147* Getting nerves_system_mangopi_mq_pro (Hex package)148* Getting nerves_system_qemu_aarch64 (Hex package)149* Getting nerves_system_rpi0 (Hex package)150* Getting nerves_system_rpi4 (Hex package)151* Getting nerves_system_rpi5 (Hex package)152* Getting nerves_system_trellis (Hex package)153* Getting nerves_system_x86_64 (Hex package)154* Getting nerves_system_br (Hex package)155* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)156* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)157* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)158* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)159* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)160* Getting nerves_logging (Hex package)161* Getting nerves_uevent (Hex package)162* Getting uboot_env (Hex package)163* Getting elixir_make (Hex package)164* Getting property_table (Hex package)165* Getting circular_buffer (Hex package)166* Getting interactive_cmd (Hex package)167* Getting nerves_discovery (Hex package)168* Getting tablet (Hex package)169* Getting chrome_remote_interface (Hex package)170* Getting cowboy (Hex package)171* Getting erlexec (Hex package)172* Getting exexec (Hex package)173* Getting jason (Hex package)174* Getting plug (Hex package)175* Getting plug_cowboy (Hex package)176* Getting cowboy_telemetry (Hex package)177* Getting telemetry (Hex package)178* Getting mime (Hex package)179* Getting plug_crypto (Hex package)180* Getting cowlib (Hex package)181* Getting ranch (Hex package)182* Getting hackney (Hex package)183* Getting poison (Hex package)184* Getting websockex (Hex package)185* Getting certifi (Hex package)186* Getting idna (Hex package)187* Getting metrics (Hex package)188* Getting mimerl (Hex package)189* Getting parse_trans (Hex package)190* Getting ssl_verify_fun (Hex package)191* Getting unicode_util_compat (Hex package)192Found retired packages, see above for details193Found packages with security advisories, see above for details194 warning: String.strip/1 is deprecated. Use String.trim/1 instead195 │196 4 │ @version File.read!("VERSION") |> String.strip197 │ ~198 │199 └─ /work/proj/deps_rpi0/poison/mix.exs:4:44: Poison.Mixfile (module)200201 warning: using single-quoted strings to represent charlists is deprecated.202 Use ~c"" if you indeed want a charlist or use "" instead.203 You may run "mix format --migrate" to change all single-quoted204 strings to use the ~c sigil and fix this warning.205 │206 21 │ defp elixirc_paths(:test), do: ['lib', 'test/support']207 │ ~208 │209 └─ /work/proj/deps_rpi0/websockex/mix.exs:21:35210211 warning: using single-quoted strings to represent charlists is deprecated.212 Use ~c"" if you indeed want a charlist or use "" instead.213 You may run "mix format --migrate" to change all single-quoted214 strings to use the ~c sigil and fix this warning.215 │216 21 │ defp elixirc_paths(:test), do: ['lib', 'test/support']217 │ ~218 │219 └─ /work/proj/deps_rpi0/websockex/mix.exs:21:42220221 warning: using single-quoted strings to represent charlists is deprecated.222 Use ~c"" if you indeed want a charlist or use "" instead.223 You may run "mix format --migrate" to change all single-quoted224 strings to use the ~c sigil and fix this warning.225 │226 22 │ defp elixirc_paths(_), do: ['lib']227 │ ~228 │229 └─ /work/proj/deps_rpi0/websockex/mix.exs:22:31230231==> nerves_system_br232Generated nerves_system_br app233==> mime234Compiling 2 files (.ex)235Generated mime app236==> circular_buffer237Compiling 1 file (.ex)238Generated circular_buffer app239==> jason240Compiling 10 files (.ex)241Generated jason app242==> poison243Compiling 4 files (.ex)244 warning: using single-quoted strings to represent charlists is deprecated.245 Use ~c"" if you indeed want a charlist or use "" instead.246 You may run "mix format --migrate" to change all single-quoted247 strings to use the ~c sigil and fix this warning.248 │249 93 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do250 │ ~251 │252 └─ lib/poison/encoder.ex:93:31253254 warning: using single-quoted strings to represent charlists is deprecated.255 Use ~c"" if you indeed want a charlist or use "" instead.256 You may run "mix format --migrate" to change all single-quoted257 strings to use the ~c sigil and fix this warning.258 │259 93 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do260 │ ~261 │262 └─ lib/poison/encoder.ex:93:48263264 warning: using single-quoted strings to represent charlists is deprecated.265 Use ~c"" if you indeed want a charlist or use "" instead.266 You may run "mix format --migrate" to change all single-quoted267 strings to use the ~c sigil and fix this warning.268 │269 139 │ defp chunk_size(<<char>> <> _, _mode, acc) when char <= 0x1F or char in '"\\' do270 │ ~271 │272 └─ lib/poison/encoder.ex:139:75273274 warning: using single-quoted strings to represent charlists is deprecated.275 Use ~c"" if you indeed want a charlist or use "" instead.276 You may run "mix format --migrate" to change all single-quoted277 strings to use the ~c sigil and fix this warning.278 │279 77 │ defp value(<<char, _ :: binary>> = string, pos, _keys) when char in '-0123456789' do280 │ ~281 │282 └─ lib/poison/parser.ex:77:71283284 warning: using single-quoted strings to represent charlists is deprecated.285 Use ~c"" if you indeed want a charlist or use "" instead.286 You may run "mix format --migrate" to change all single-quoted287 strings to use the ~c sigil and fix this warning.288 │289 155 │ defp number_int(<<char, _ :: binary>> = string, pos, acc) when char in '123456789' do290 │ ~291 │292 └─ lib/poison/parser.ex:155:74293294 warning: using single-quoted strings to represent charlists is deprecated.295 Use ~c"" if you indeed want a charlist or use "" instead.296 You may run "mix format --migrate" to change all single-quoted297 strings to use the ~c sigil and fix this warning.298 │299 171 │ defp number_exp(<<e>> <> rest, frac, pos, acc) when e in 'eE' do300 │ ~301 │302 └─ lib/poison/parser.ex:171:60303304 warning: using single-quoted strings to represent charlists is deprecated.305 Use ~c"" if you indeed want a charlist or use "" instead.306 You may run "mix format --migrate" to change all single-quoted307 strings to use the ~c sigil and fix this warning.308 │309 197 │ defp number_digits(<<char>> <> rest = string, pos) when char in '0123456789' do310 │ ~311 │312 └─ lib/poison/parser.ex:197:67313314 warning: using single-quoted strings to represent charlists is deprecated.315 Use ~c"" if you indeed want a charlist or use "" instead.316 You may run "mix format --migrate" to change all single-quoted317 strings to use the ~c sigil and fix this warning.318 │319 205 │ defp number_digits_count(<<char>> <> rest, acc) when char in '0123456789' do320 │ ~321 │322 └─ lib/poison/parser.ex:205:64323324 warning: using single-quoted strings to represent charlists is deprecated.325 Use ~c"" if you indeed want a charlist or use "" instead.326 You may run "mix format --migrate" to change all single-quoted327 strings to use the ~c sigil and fix this warning.328 │329 229 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do330 │ ~331 │332 └─ lib/poison/parser.ex:229:31333334 warning: using single-quoted strings to represent charlists is deprecated.335 Use ~c"" if you indeed want a charlist or use "" instead.336 You may run "mix format --migrate" to change all single-quoted337 strings to use the ~c sigil and fix this warning.338 │339 229 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do340 │ ~341 │342 └─ lib/poison/parser.ex:229:44343344 warning: using single-quoted strings to represent charlists is deprecated.345 Use ~c"" if you indeed want a charlist or use "" instead.346 You may run "mix format --migrate" to change all single-quoted347 strings to use the ~c sigil and fix this warning.348 │349 239 │ when a1 in 'dD' and a2 in 'dD'350 │ ~351 │352 └─ lib/poison/parser.ex:239:16353354 warning: using single-quoted strings to represent charlists is deprecated.355 Use ~c"" if you indeed want a charlist or use "" instead.356 You may run "mix format --migrate" to change all single-quoted357 strings to use the ~c sigil and fix this warning.358 │359 239 │ when a1 in 'dD' and a2 in 'dD'360 │ ~361 │362 └─ lib/poison/parser.ex:239:31363364 warning: using single-quoted strings to represent charlists is deprecated.365 Use ~c"" if you indeed want a charlist or use "" instead.366 You may run "mix format --migrate" to change all single-quoted367 strings to use the ~c sigil and fix this warning.368 │369 240 │ and (b1 in '89abAB')370 │ ~371 │372 └─ lib/poison/parser.ex:240:16373374 warning: using single-quoted strings to represent charlists is deprecated.375 Use ~c"" if you indeed want a charlist or use "" instead.376 You may run "mix format --migrate" to change all single-quoted377 strings to use the ~c sigil and fix this warning.378 │379 274 │ defp skip_whitespace(<<char>> <> rest, pos) when char in '\s\n\t\r' do380 │ ~381 │382 └─ lib/poison/parser.ex:274:60383384 warning: Application.get_env/2 is discouraged in the module body, use Application.compile_env/3 instead385 │386 22 │ if Application.get_env(:poison, :native) do387 │ ~388 │389 └─ lib/poison/parser.ex:22:18: Poison.Parser (module)390391 warning: use Bitwise is deprecated. import Bitwise instead392 │393 26 │ use Bitwise394 │ ~~~~~~~~~~~395 │396 └─ lib/poison/parser.ex:26: Poison.Parser (module)397398 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator399 │400 199 │ <<digits :: binary-size(count), rest :: binary>> = string401 │ ~402 │403 └─ lib/poison/parser.ex:199:29: Poison.Parser.number_digits/2404405 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator406 │407 225 │ <<chunk :: binary-size(count), rest :: binary>> = string408 │ ~409 │410 └─ lib/poison/parser.ex:225:28: Poison.Parser.string_continue/3411412 warning: use Bitwise is deprecated. import Bitwise instead413 │414 83 │ use Bitwise415 │ ~~~~~~~~~~~416 │417 └─ lib/poison/encoder.ex:83: Poison.Encoder.BitString (module)418419 warning: the variable "size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator420 │421 135 │ <<chunk :: binary-size(size), rest :: binary>> = string422 │ ~423 │424 └─ lib/poison/encoder.ex:135:28: Poison.Encoder.BitString.escape/2425426 warning: Integer.to_char_list/2 is deprecated. Use Integer.to_charlist/2 instead427 │428 173 │ case Integer.to_char_list(char, 16) do429 │ ~430 │431 └─ lib/poison/encoder.ex:173:18: Poison.Encoder.BitString.seq/1432433Generated poison app434==> websockex435could not compile dependency :websockex, "mix compile" failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile websockex --force", update it with "mix deps.update websockex" or clean it with "mix deps.clean websockex"436==> nerves_compatibility_test437** (Mix) :elixirc_paths should be a list of string paths, got: [~c"lib"]