Build log
nerves_system_x86_64
ex_abci_proto 0.10.0-alpha · fail · run ex_abci_proto-0.10.0-alpha-1791172399692
150 of 150 lines
1Resolving Hex dependencies...2Resolution completed in 0.156s3Unchanged:4 circular_buffer 1.1.05 cowboy 2.6.3 VULNERABLE!6 EEF-CVE-2026-8466 (HIGH)7 aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x88 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy9 https://osv.dev/vulnerability/EEF-CVE-2026-84661011 EEF-CVE-2026-65624 (MEDIUM)12 aka: CVE-2026-6562413 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion14 https://osv.dev/vulnerability/EEF-CVE-2026-656241516 GHSA-w4f7-4cxr-rv3c (MEDIUM)17 aka: CVE-2026-43966, EEF-CVE-2026-4396618 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability19 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c20 cowlib 2.7.3 VULNERABLE!21 EEF-CVE-2026-59248 (HIGH)22 aka: CVE-2026-5924823 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS24 https://osv.dev/vulnerability/EEF-CVE-2026-592482526 EEF-CVE-2026-43970 (HIGH)27 aka: CVE-2026-43970, GHSA-84f2-rp86-235p28 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame29 https://osv.dev/vulnerability/EEF-CVE-2026-439703031 EEF-CVE-2026-43968 (MEDIUM)32 aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r33 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/134 https://osv.dev/vulnerability/EEF-CVE-2026-439683536 EEF-CVE-2026-7790 (HIGH)37 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6538 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS39 https://osv.dev/vulnerability/EEF-CVE-2026-779040 elixir_make 0.10.041 ex_abci_proto 0.10.0-alpha42 google_protos 0.4.043 grpc 0.4.0-alpha.2 VULNERABLE!44 EEF-CVE-2026-48854 (HIGH)45 aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj46 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc47 https://osv.dev/vulnerability/EEF-CVE-2026-4885448 gun 1.3.3 VULNERABLE!49 EEF-CVE-2026-43973 (HIGH)50 aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7751 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion52 https://osv.dev/vulnerability/EEF-CVE-2026-439735354 GHSA-w4f7-4cxr-rv3c (MEDIUM)55 aka: CVE-2026-43966, EEF-CVE-2026-4396656 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability57 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c58 interactive_cmd 0.1.459 nerves 2.0.0-pre.260 nerves_discovery 0.1.561 nerves_logging 0.2.462 nerves_runtime 0.13.1363 nerves_system_bbb 2.30.264 nerves_system_br 1.34.465 nerves_system_mangopi_mq_pro 0.17.266 nerves_system_qemu_aarch64 0.4.267 nerves_system_rpi0 2.1.268 nerves_system_rpi4 2.1.269 nerves_system_rpi5 2.1.270 nerves_system_trellis 0.5.071 nerves_system_x86_64 1.34.272 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.173 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.174 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.175 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.176 nerves_toolchain_x86_64_nerves_linux_musl 15.3.177 nerves_uevent 0.1.778 property_table 0.3.479 protobuf 0.17.080 ranch 1.7.181 ring_logger 0.11.782 tablet 0.3.383 toolshed 0.5.084 uboot_env 1.0.285* Getting ex_abci_proto (Hex package)86* Getting nerves (Hex package)87* Getting ring_logger (Hex package)88* Getting toolshed (Hex package)89* Getting nerves_runtime (Hex package)90* Getting nerves_system_bbb (Hex package)91* Getting nerves_system_mangopi_mq_pro (Hex package)92* Getting nerves_system_qemu_aarch64 (Hex package)93* Getting nerves_system_rpi0 (Hex package)94* Getting nerves_system_rpi4 (Hex package)95* Getting nerves_system_rpi5 (Hex package)96* Getting nerves_system_trellis (Hex package)97* Getting nerves_system_x86_64 (Hex package)98* Getting nerves_system_br (Hex package)99* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)100* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)101* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)102* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)103* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)104* Getting nerves_logging (Hex package)105* Getting nerves_uevent (Hex package)106* Getting uboot_env (Hex package)107* Getting elixir_make (Hex package)108* Getting property_table (Hex package)109* Getting circular_buffer (Hex package)110* Getting interactive_cmd (Hex package)111* Getting nerves_discovery (Hex package)112* Getting tablet (Hex package)113* Getting google_protos (Hex package)114* Getting grpc (Hex package)115* Getting cowboy (Hex package)116* Getting gun (Hex package)117* Getting protobuf (Hex package)118* Getting cowlib (Hex package)119* Getting ranch (Hex package)120Found packages with security advisories, see above for details121===> Analyzing applications...122===> Compiling ranch123 ┌─ src/ranch_ssl.erl:124 │125 142 │ case ssl:ssl_accept(CSocket, Opts, Timeout) of126 │ ╰── Warning: ssl:ssl_accept/3 is removed; use ssl:handshake/1,2,3 instead127128129 ┌─ src/ranch_conns_sup.erl:130 │131 80 │ catch erlang:send(SupPid, {?MODULE, active_connections, self(), Tag},132 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.133Compile directive 'nowarn_deprecated_catch' can be used to suppress134warnings in selected modules.135136137==> protobuf138Compiling 50 files (.ex)139Generated protobuf app140==> nerves_compatibility_test141===> Analyzing applications...142===> Compiling cowlib143===> Compiling src/cow_sse.erl failed144 ┌─ src/cow_sse.erl:145 │146 56 │ -> {event, parsed_event(), State} | {more, State}.147 │ ╰── type variable 'State' is only used once (is unbound)148149150** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/x86_64/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"