Build log
host
crudjt 1.0.1 · fail · run crudjt-1.0.1-1791089566996
446 of 446 lines
1Resolving Hex dependencies...2Resolution completed in 0.312s3Unchanged:4 circular_buffer 1.1.05 cowboy 2.19.06 cowlib 2.20.0 VULNERABLE!7 EEF-CVE-2026-43966 (MEDIUM)8 aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c9 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/210 https://osv.dev/vulnerability/EEF-CVE-2026-439661112 EEF-CVE-2026-43969 (LOW)13 aka: CVE-2026-43969, GHSA-g2wm-735q-3f5614 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/115 https://osv.dev/vulnerability/EEF-CVE-2026-4396916 crudjt 1.0.117 elixir_make 0.10.018 flow 1.2.419 gen_stage 1.3.220 googleapis 0.1.021 grpc 0.11.5 VULNERABLE!22 EEF-CVE-2026-53430 (HIGH)23 aka: CVE-2026-53430, GHSA-6ccx-9c9f-327w24 grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/125 https://osv.dev/vulnerability/EEF-CVE-2026-534302627 EEF-CVE-2026-48854 (HIGH)28 aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj29 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc30 https://osv.dev/vulnerability/EEF-CVE-2026-488543132 EEF-CVE-2026-48853 (CRITICAL)33 aka: CVE-2026-48853, GHSA-grp7-v8xh-rj7h34 Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc35 https://osv.dev/vulnerability/EEF-CVE-2026-488533637 EEF-CVE-2026-48599 (HIGH)38 aka: CVE-2026-48599, GHSA-mwr4-5g34-j5cq39 Authorization bypass via path binding override in elixir-grpc/grpc HTTP transcoding40 https://osv.dev/vulnerability/EEF-CVE-2026-4859941 gun 2.6.0 VULNERABLE!42 GHSA-w4f7-4cxr-rv3c (MEDIUM)43 aka: CVE-2026-43966, EEF-CVE-2026-4396644 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability45 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c46 hpax 1.1.047 interactive_cmd 0.1.448 jason 1.4.549 mint 1.11.050 msgpax 2.4.051 nerves 2.0.0-pre.252 nerves_discovery 0.1.553 nerves_logging 0.2.454 nerves_runtime 0.13.1355 nerves_system_bbb 2.30.256 nerves_system_br 1.34.457 nerves_system_mangopi_mq_pro 0.17.258 nerves_system_qemu_aarch64 0.4.259 nerves_system_rpi0 2.1.260 nerves_system_rpi4 2.1.261 nerves_system_rpi5 2.1.262 nerves_system_trellis 0.5.063 nerves_system_x86_64 1.34.264 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.165 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.166 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.167 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.168 nerves_toolchain_x86_64_nerves_linux_musl 15.3.169 nerves_uevent 0.1.770 property_table 0.3.471 protobuf 0.17.072 ranch 2.3.073 ring_logger 0.11.774 rustler 0.29.175 tablet 0.3.376 telemetry 1.4.277 toml 0.7.078 toolshed 0.5.079 uboot_env 1.0.280Found packages with security advisories, see above for details81All dependencies have been fetched82==> googleapis83Compiling 45 files (.ex)84Generated googleapis app85==> flow86Compiling 9 files (.ex)87Generated flow app88==> grpc89Compiling 1 file (.erl)90warning: "xref: [exclude: ...]" in your mix.exs file is deprecated, instead use: "elixirc_options: [no_warn_undefined: ...]"91 (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:243: Mix.Tasks.Compile.Elixir.xref_exclude_opts/292 (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:142: Mix.Tasks.Compile.Elixir.run/193 (mix 1.20.3) lib/mix/task.ex:502: anonymous fn/3 in Mix.Task.run_task/594 (mix 1.20.3) lib/mix/task.compiler.ex:299: Mix.Task.Compiler.run_compiler/295 (mix 1.20.3) lib/mix/task.compiler.ex:287: Mix.Task.Compiler.run/496 (mix 1.20.3) lib/mix/tasks/compile.all.ex:75: Mix.Tasks.Compile.All.do_run/29798Compiling 65 files (.ex)99 warning: the variable "bytes_length" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator100 │101 346 │ <<head::binary-size(bytes_length), tail::binary>> -> {head, tail}102 │ ~103 │104 └─ lib/grpc/client/adapters/mint/connection_process/connection_process.ex:346:27: GRPC.Client.Adapters.Mint.ConnectionProcess.chunk_body/2105106 warning: unused require Logger107 │108 113 │ require Logger109 │ ~110 │111 └─ lib/grpc/server.ex:113:3112113 warning: a struct for Protobuf.Protoc.Context is expected on struct update:114115 %Protobuf.Protoc.Context{116 ctx117 | syntax: syntax(desc.syntax),118 package: desc.package,119 dep_type_mapping: get_dep_type_mapping(ctx, desc.dependency, desc.name)120 }121122 but got type:123124 dynamic()125126 where "ctx" was given the type:127128 # type: dynamic()129 # from: lib/grpc/protoc/generator.ex:43:36130 ctx131132 when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"133134 type warning found at:135 │136 45 │ %Context{137 │ ~138 │139 └─ lib/grpc/protoc/generator.ex:45:7: GRPC.Protoc.Generator.generate_module_definitions/2140141 warning: Protobuf.Decoder.decode/2 is undefined or private. Did you mean:142143 * decode/3144145 │146 47 │ request = Protobuf.Decoder.decode(bin, Google.Protobuf.Compiler.CodeGeneratorRequest)147 │ ~148 │149 └─ lib/grpc/protoc/cli.ex:47:32: GRPC.Protoc.CLI.main/1150151 warning: a struct for Protobuf.Protoc.Context is expected on struct update:152153 %Protobuf.Protoc.Context{ctx | plugins: String.split(plugins, "+")}154155 but got type:156157 dynamic()158159 where "ctx" was given the type:160161 # type: dynamic()162 # from: lib/grpc/protoc/cli.ex:86:43163 ctx164165 when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"166167 type warning found at:168 │169 87 │ %Context{ctx | plugins: String.split(plugins, "+")}170 │ ~171 │172 └─ lib/grpc/protoc/cli.ex:87:5: GRPC.Protoc.CLI.parse_param/2173174 warning: a struct for Protobuf.Protoc.Context is expected on struct update:175176 %Protobuf.Protoc.Context{ctx | gen_descriptors?: true}177178 but got type:179180 dynamic()181182 where "ctx" was given the type:183184 # type: dynamic()185 # from: lib/grpc/protoc/cli.ex:90:49186 ctx187188 when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"189190 type warning found at:191 │192 93 │ %Context{ctx | gen_descriptors?: true}193 │ ~194 │195 └─ lib/grpc/protoc/cli.ex:93:9: GRPC.Protoc.CLI.parse_param/2196197 warning: a struct for Protobuf.Protoc.Context is expected on struct update:198199 %Protobuf.Protoc.Context{ctx | package_prefix: package}200201 but got type:202203 dynamic()204205 where "ctx" was given the type:206207 # type: dynamic()208 # from: lib/grpc/protoc/cli.ex:100:50209 ctx210211 when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"212213 type warning found at:214 │215 104 │ %Context{ctx | package_prefix: package}216 │ ~217 │218 └─ lib/grpc/protoc/cli.ex:104:7: GRPC.Protoc.CLI.parse_param/2219220 warning: a struct for Protobuf.Protoc.Context is expected on struct update:221222 %Protobuf.Protoc.Context{ctx | transform_module: Module.concat([module])}223224 but got type:225226 dynamic()227228 where "ctx" was given the type:229230 # type: dynamic()231 # from: lib/grpc/protoc/cli.ex:108:51232 ctx233234 when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"235236 type warning found at:237 │238 109 │ %Context{ctx | transform_module: Module.concat([module])}239 │ ~240 │241 └─ lib/grpc/protoc/cli.ex:109:5: GRPC.Protoc.CLI.parse_param/2242243 warning: a struct for Protobuf.Protoc.Context is expected on struct update:244245 %Protobuf.Protoc.Context{ctx | one_file_per_module?: true}246247 but got type:248249 dynamic()250251 where "ctx" was given the type:252253 # type: dynamic()254 # from: lib/grpc/protoc/cli.ex:112:53255 ctx256257 when defining the variable "ctx", you must also pattern match on "%Protobuf.Protoc.Context{}"258259 type warning found at:260 │261 115 │ %Context{ctx | one_file_per_module?: true}262 │ ~263 │264 └─ lib/grpc/protoc/cli.ex:115:9: GRPC.Protoc.CLI.parse_param/2265266 warning: Protobuf.Decoder.decode/2 is undefined or private. Did you mean:267268 * decode/3269270 │271 27 │ Protobuf.Decoder.decode(binary, module)272 │ ~273 │274 └─ lib/grpc/codec/web_text.ex:27:22: GRPC.Codec.WebText.decode/2275276 warning: a struct for GRPC.Client.Connection is expected on struct update:277278 %GRPC.Client.Connection{279 base_state280 | lb_mod: lb_mod,281 lb_state: new_lb_state,282 virtual_channel: ch,283 real_channels: real_channels284 }285286 but got type:287288 dynamic(%{..., virtual_channel: term()})289290 where "base_state" was given the type:291292 # type: dynamic(%{..., virtual_channel: term()})293 # from: lib/grpc/client/connection.ex:417:11294 build_real_channels(addresses, base_state.virtual_channel, norm_opts, adapter)295296 when defining the variable "base_state", you must also pattern match on "%GRPC.Client.Connection{}"297298 type warning found at:299 │300 423 │ %__MODULE__{301 │ ~302 │303 └─ lib/grpc/client/connection.ex:423:12: GRPC.Client.Connection.build_balanced_state/6304305 warning: a struct for GRPC.Client.Connection is expected on struct update:306307 %GRPC.Client.Connection{308 base_state309 | virtual_channel: ch,310 real_channels: %{<<to_string(host)::binary, ":", to_string(port)::binary>> => ch}311 }312313 but got type:314315 dynamic(%{..., virtual_channel: term()})316317 where "base_state" was given the type:318319 # type: dynamic(%{..., virtual_channel: term()})320 # from: lib/grpc/client/connection.ex:441:8321 vc = base_state.virtual_channel322323 when defining the variable "base_state", you must also pattern match on "%GRPC.Client.Connection{}"324325 type warning found at:326 │327 446 │ %__MODULE__{328 │ ~329 │330 └─ lib/grpc/client/connection.ex:446:10: GRPC.Client.Connection.build_direct_state/4331332 warning: the following clause will never match:333334 nil ->335336 because it attempts to match on the result of:337338 scheme339340 which has type:341342 dynamic(not false and not nil)343344 type warning found at:345 │346 132 │ nil ->347 │ ~~~~~~348 │349 └─ lib/grpc/client/resolver.ex:132: GRPC.Client.Resolver.resolve/1350351 warning: a struct for GRPC.Channel is expected on struct update:352353 %GRPC.Channel{virtual_channel | host: host, port: port}354355 but got type:356357 dynamic()358359 where "virtual_channel" was given the type:360361 # type: dynamic()362 # from: lib/grpc/client/connection.ex:457:39363 virtual_channel364365 when defining the variable "virtual_channel", you must also pattern match on "%GRPC.Channel{}"366367 type warning found at:368 │369 460 │ %Channel{virtual_channel | host: host, port: port},370 │ ~371 │372 └─ lib/grpc/client/connection.ex:460:14: GRPC.Client.Connection.build_real_channels/4373374 warning: a struct for GRPC.Channel is expected on struct update:375376 %GRPC.Channel{vc | host: host, port: port}377378 but got type:379380 dynamic()381382 where "vc" was given the type:383384 # type: dynamic()385 # from: lib/grpc/client/connection.ex:525:29386 vc387388 when defining the variable "vc", you must also pattern match on "%GRPC.Channel{}"389390 type warning found at:391 │392 526 │ %Channel{vc | host: host, port: port}393 │ ~394 │395 └─ lib/grpc/client/connection.ex:526:5: GRPC.Client.Connection.connect_real_channel/5396397 warning: incompatible types given to pick_channel/1:398399 pick_channel(opts)400401 given types:402403 -dynamic(empty_list() or non_empty_list(term(), term()))-404405 but expected one of:406407 %GRPC.Channel{}408409 where "opts" was given the type:410411 # type: dynamic(empty_list() or non_empty_list(term(), term()))412 # from: lib/grpc/client/connection.ex:178:46413 Keyword.merge(opts, ref: ref)414415 type warning found at:416 │417 188 │ case pick_channel(opts) do418 │ ~419 │420 └─ lib/grpc/client/connection.ex:188:18: GRPC.Client.Connection.connect/2421422Generated grpc app423424The `:rustler` compiler has been deprecated since v0.22.0 and will be425removed in v1.0.426427To remove this warning, please consult the CHANGELOG for v0.22.0.428429==> crudjt430Compiling 10 files (.ex)431 warning: variable "output" is unused (there is a variable with the same name in the context, use the pin operator (^) to match on it or prefix this variable with underscore if it is not meant to be used)432 │433 87 │ output =434 │ ~435 │436 └─ lib/cache.ex:87:11: CRUDJT_Cache.process_cached_token/4437438439== Compilation error in file lib/crudjt.ex ==440** (ErlangError) Erlang error: :enoent441 (elixir 1.20.3) lib/system.ex:1141: System.cmd("cargo", ["metadata", "--format-version=1"], [cd: "native/crudjt"])442 (rustler 0.29.1) lib/rustler/compiler/config.ex:83: Rustler.Compiler.Config.metadata!/1443 (rustler 0.29.1) lib/rustler/compiler/config.ex:70: Rustler.Compiler.Config.build/1444 (rustler 0.29.1) lib/rustler/compiler.ex:9: Rustler.Compiler.compile_crate/2445 lib/crudjt.ex:6: (module)446could not compile dependency :crudjt, "mix compile" failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile crudjt --force", update it with "mix deps.update crudjt" or clean it with "mix deps.clean crudjt"