Build log
host
dc_metrics 0.1.2 · fail · run dc_metrics-0.1.2-1791118949818
148 of 148 lines
1Resolving Hex dependencies...2Resolution completed in 0.427s3Unchanged:4 certifi 2.15.05 circular_buffer 1.1.06 cowboy 2.6.3 VULNERABLE!7 EEF-CVE-2026-8466 (HIGH)8 aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x89 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy10 https://osv.dev/vulnerability/EEF-CVE-2026-84661112 EEF-CVE-2026-65624 (MEDIUM)13 aka: CVE-2026-6562414 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion15 https://osv.dev/vulnerability/EEF-CVE-2026-656241617 GHSA-w4f7-4cxr-rv3c (MEDIUM)18 aka: CVE-2026-43966, EEF-CVE-2026-4396619 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability20 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c21 cowlib 2.7.3 VULNERABLE!22 EEF-CVE-2026-59248 (HIGH)23 aka: CVE-2026-5924824 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS25 https://osv.dev/vulnerability/EEF-CVE-2026-592482627 EEF-CVE-2026-43970 (HIGH)28 aka: CVE-2026-43970, GHSA-84f2-rp86-235p29 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame30 https://osv.dev/vulnerability/EEF-CVE-2026-439703132 EEF-CVE-2026-43968 (MEDIUM)33 aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r34 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/135 https://osv.dev/vulnerability/EEF-CVE-2026-439683637 EEF-CVE-2026-7790 (HIGH)38 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6539 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS40 https://osv.dev/vulnerability/EEF-CVE-2026-779041 dc_metrics 0.1.242 elixir_make 0.10.043 google_api_pub_sub 0.27.044 google_gax 0.4.145 goth 1.1.046 grpc 0.3.1 VULNERABLE!47 EEF-CVE-2026-48854 (HIGH)48 aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj49 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc50 https://osv.dev/vulnerability/EEF-CVE-2026-4885451 gun 1.3.3 VULNERABLE!52 EEF-CVE-2026-43973 (HIGH)53 aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7754 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion55 https://osv.dev/vulnerability/EEF-CVE-2026-439735657 GHSA-w4f7-4cxr-rv3c (MEDIUM)58 aka: CVE-2026-43966, EEF-CVE-2026-4396659 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability60 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c61 hackney 1.25.0 VULNERABLE!62 EEF-CVE-2026-47071 (HIGH)63 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr64 SOCKS5 TLS upgrade ignores caller timeout in hackney65 https://osv.dev/vulnerability/EEF-CVE-2026-470716667 EEF-CVE-2026-47076 (MEDIUM)68 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq69 SSRF allowlist bypass via percent-encoded host in hackney70 https://osv.dev/vulnerability/EEF-CVE-2026-470767172 EEF-CVE-2026-47069 (LOW)73 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw274 CRLF injection in cookie domain/path options in hackney75 https://osv.dev/vulnerability/EEF-CVE-2026-470697677 EEF-CVE-2026-47075 (MEDIUM)78 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf79 CR/LF injection in query parameter in hackney80 https://osv.dev/vulnerability/EEF-CVE-2026-4707581 httpoison 1.8.282 idna 6.1.183 interactive_cmd 0.1.484 jason 1.4.585 joken 2.7.086 jose 1.11.1287 metrics 1.0.188 mime 1.6.089 mimerl 1.5.090 nerves 2.0.0-pre.291 nerves_discovery 0.1.592 nerves_logging 0.2.493 nerves_runtime 0.13.1394 nerves_system_bbb 2.30.295 nerves_system_br 1.34.496 nerves_system_mangopi_mq_pro 0.17.297 nerves_system_qemu_aarch64 0.4.298 nerves_system_rpi0 2.1.299 nerves_system_rpi4 2.1.2100 nerves_system_rpi5 2.1.2101 nerves_system_trellis 0.5.0102 nerves_system_x86_64 1.34.2103 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1104 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1105 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1106 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1107 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1108 nerves_uevent 0.1.7109 parse_trans 3.4.1110 poison 4.0.1111 property_table 0.3.4112 protobuf 0.7.1113 ranch 1.7.1114 ring_logger 0.11.7115 ssl_verify_fun 1.1.7116 tablet 0.3.3117 tesla 1.21.3118 toolshed 0.5.0119 uboot_env 1.0.2120 unicode_util_compat 0.7.1121Found packages with security advisories, see above for details122All dependencies have been fetched123===> Analyzing applications...124===> Compiling ranch125 ┌─ src/ranch_ssl.erl:126 │127 142 │ case ssl:ssl_accept(CSocket, Opts, Timeout) of128 │ ╰── Warning: ssl:ssl_accept/3 is removed; use ssl:handshake/1,2,3 instead129130131 ┌─ src/ranch_conns_sup.erl:132 │133 80 │ catch erlang:send(SupPid, {?MODULE, active_connections, self(), Tag},134 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.135Compile directive 'nowarn_deprecated_catch' can be used to suppress136warnings in selected modules.137138139===> Analyzing applications...140===> Compiling cowlib141===> Compiling src/cow_sse.erl failed142 ┌─ src/cow_sse.erl:143 │144 56 │ -> {event, parsed_event(), State} | {more, State}.145 │ ╰── type variable 'State' is only used once (is unbound)146147148** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"