Build log
host
effusion 0.2.0 · fail · run effusion-0.2.0-1791169669864
171 of 171 lines
1Resolving Hex dependencies...2Resolution completed in 0.817s3Unchanged:4 absinthe 1.5.5 VULNERABLE!5 EEF-CVE-2026-43967 (HIGH)6 aka: CVE-2026-43967, GHSA-9mhv-8h52-q7q27 Quadratic fragment-name uniqueness check causes denial of service in absinthe8 https://osv.dev/vulnerability/EEF-CVE-2026-43967910 EEF-CVE-2026-42793 (HIGH)11 aka: CVE-2026-42793, GHSA-qf4g-9fqq-mmm712 Atom table exhaustion via attacker-controlled GraphQL SDL names in absinthe13 https://osv.dev/vulnerability/EEF-CVE-2026-4279314 absinthe_phoenix 1.5.015 absinthe_plug 1.5.8 VULNERABLE!16 EEF-CVE-2026-42794 (LOW)17 aka: CVE-2026-42794, GHSA-c62g-j346-39v518 Reflected XSS via backslash bypass in GraphiQL js_escape in absinthe_plug19 https://osv.dev/vulnerability/EEF-CVE-2026-4279420 certifi 2.15.021 circular_buffer 1.1.022 combine 0.10.023 cors_plug 2.0.324 cowboy 2.19.025 cowboy_telemetry 0.3.126 cowlib 2.20.0 VULNERABLE!27 EEF-CVE-2026-43966 (MEDIUM)28 aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c29 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/230 https://osv.dev/vulnerability/EEF-CVE-2026-439663132 EEF-CVE-2026-43969 (LOW)33 aka: CVE-2026-43969, GHSA-g2wm-735q-3f5634 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/135 https://osv.dev/vulnerability/EEF-CVE-2026-4396936 db_connection 2.10.237 decimal 1.9.0 VULNERABLE!38 EEF-CVE-2026-32686 (MEDIUM)39 aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v40 Unbounded exponent in decimal enables unauthenticated DoS41 https://osv.dev/vulnerability/EEF-CVE-2026-3268642 ecto 3.10.343 ecto_network 1.2.044 ecto_sql 3.10.245 effusion 0.2.046 elixir_make 0.10.047 ex_bencode 2.0.248 expo 1.1.149 gen_stage 0.14.350 gettext 0.26.251 hackney 1.25.0 VULNERABLE!52 EEF-CVE-2026-47071 (HIGH)53 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr54 SOCKS5 TLS upgrade ignores caller timeout in hackney55 https://osv.dev/vulnerability/EEF-CVE-2026-470715657 EEF-CVE-2026-47076 (MEDIUM)58 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq59 SSRF allowlist bypass via percent-encoded host in hackney60 https://osv.dev/vulnerability/EEF-CVE-2026-470766162 EEF-CVE-2026-47069 (LOW)63 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw264 CRLF injection in cookie domain/path options in hackney65 https://osv.dev/vulnerability/EEF-CVE-2026-470696667 EEF-CVE-2026-47075 (MEDIUM)68 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf69 CR/LF injection in query parameter in hackney70 https://osv.dev/vulnerability/EEF-CVE-2026-4707571 httpoison 1.8.272 httpotion 3.0.3 RETIRED!73 (deprecated) Not really maintained, please check out Tesla74 ibrowse 4.5.075 idna 6.1.176 int_set 1.5.277 interactive_cmd 0.1.478 jason 1.4.579 logger_file_backend 0.0.1480 metatorrent 1.0.081 metrics 1.0.182 mime 2.0.783 mimerl 1.5.084 nerves 2.0.0-pre.285 nerves_discovery 0.1.586 nerves_logging 0.2.487 nerves_runtime 0.13.1388 nerves_system_bbb 2.30.289 nerves_system_br 1.34.490 nerves_system_mangopi_mq_pro 0.17.291 nerves_system_qemu_aarch64 0.4.292 nerves_system_rpi0 2.1.293 nerves_system_rpi4 2.1.294 nerves_system_rpi5 2.1.295 nerves_system_trellis 0.5.096 nerves_system_x86_64 1.34.297 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.198 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.199 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1100 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1101 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1102 nerves_uevent 0.1.7103 nimble_parsec 1.4.2104 parse_trans 3.4.1105 phoenix 1.4.18 VULNERABLE!106 GHSA-p8f7-22gq-m7j9 (HIGH)107 aka: CVE-2022-42975108 Phoenix before 1.6.14 mishandles check_origin wildcarding109 https://osv.dev/vulnerability/GHSA-p8f7-22gq-m7j9110111 EEF-CVE-2026-56812 (MEDIUM)112 aka: CVE-2026-56812, GHSA-63mc-hw7g-86rr113 Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff114 https://osv.dev/vulnerability/EEF-CVE-2026-56812115116 EEF-CVE-2026-56811 (HIGH)117 aka: CVE-2026-56811, GHSA-6983-jfq8-485w118 Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service119 https://osv.dev/vulnerability/EEF-CVE-2026-56811120 phoenix_pubsub 1.1.2121 plug 1.20.3122 plug_cowboy 2.9.0123 plug_crypto 2.2.0124 postgrex 0.17.5 VULNERABLE!125 EEF-CVE-2026-32687 (HIGH)126 aka: CVE-2026-32687, GHSA-r73h-97w8-m54h127 SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3128 https://osv.dev/vulnerability/EEF-CVE-2026-32687129130 EEF-CVE-2026-58225 (LOW)131 aka: CVE-2026-58225, GHSA-4mw9-4qgj-m97w132 SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service133 https://osv.dev/vulnerability/EEF-CVE-2026-58225134 property_table 0.3.4135 ranch 1.8.1136 ring_logger 0.11.7137 ssl_verify_fun 1.1.7138 tablet 0.3.3139 telemetry 0.4.3140 timex 3.6.4141 toolshed 0.5.0142 tzdata 0.1.201805143 uboot_env 1.0.2144 unicode_util_compat 0.7.1145Found retired packages, see above for details146Found packages with security advisories, see above for details147All dependencies have been fetched148 error: undefined variable "package"149 │150 9 │ package: package,151 │ ^^^^^^^152 │153 └─ /work/proj/deps/tzdata/mix.exs:9:15: Tzdata.Mixfile.project/0154155 error: undefined variable "description"156 │157 10 │ description: description,158 │ ^^^^^^^^^^^159 │160 └─ /work/proj/deps/tzdata/mix.exs:10:19: Tzdata.Mixfile.project/0161162 error: undefined variable "deps"163 │164 11 │ deps: deps]165 │ ^^^^166 │167 └─ /work/proj/deps/tzdata/mix.exs:11:12: Tzdata.Mixfile.project/0168169Error while loading project :tzdata at /work/proj/deps/tzdata170** (CompileError) deps/tzdata/mix.exs: cannot compile module Tzdata.Mixfile (errors have been logged)171