Build log
host
fluminus_bot 0.1.0 · fail · run fluminus_bot-0.1.0-1791185280999
230 of 230 lines
1Resolving Hex dependencies...2Resolution completed in 0.313s3Unchanged:4 certifi 2.15.05 circular_buffer 1.1.06 cookie 0.1.27 cowboy 2.19.08 cowboy_telemetry 0.4.09 cowlib 2.20.0 VULNERABLE!10 EEF-CVE-2026-43966 (MEDIUM)11 aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c12 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/213 https://osv.dev/vulnerability/EEF-CVE-2026-439661415 EEF-CVE-2026-43969 (LOW)16 aka: CVE-2026-43969, GHSA-g2wm-735q-3f5617 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/118 https://osv.dev/vulnerability/EEF-CVE-2026-4396919 db_connection 2.10.220 decimal 1.9.0 VULNERABLE!21 EEF-CVE-2026-32686 (MEDIUM)22 aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v23 Unbounded exponent in decimal enables unauthenticated DoS24 https://osv.dev/vulnerability/EEF-CVE-2026-3268625 ecto 3.10.326 ecto_sql 3.10.227 elixir_make 0.10.028 ex_gram 0.71.029 ffmpex 0.6.030 floki 0.22.031 fluminus 1.4.332 fluminus_bot 0.1.033 hackney 1.25.0 VULNERABLE!34 EEF-CVE-2026-47071 (HIGH)35 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr36 SOCKS5 TLS upgrade ignores caller timeout in hackney37 https://osv.dev/vulnerability/EEF-CVE-2026-470713839 EEF-CVE-2026-47076 (MEDIUM)40 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq41 SSRF allowlist bypass via percent-encoded host in hackney42 https://osv.dev/vulnerability/EEF-CVE-2026-470764344 EEF-CVE-2026-47069 (LOW)45 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw246 CRLF injection in cookie domain/path options in hackney47 https://osv.dev/vulnerability/EEF-CVE-2026-470694849 EEF-CVE-2026-47075 (MEDIUM)50 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf51 CR/LF injection in query parameter in hackney52 https://osv.dev/vulnerability/EEF-CVE-2026-4707553 html_entities 0.4.054 html_sanitize_ex 1.3.0 VULNERABLE!55 EEF-CVE-2026-68749 (HIGH)56 aka: CVE-2026-68749, GHSA-4cx2-987x-rr2x57 Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service58 https://osv.dev/vulnerability/EEF-CVE-2026-687495960 EEF-CVE-2026-66370 (MEDIUM)61 aka: CVE-2026-66370, GHSA-w3f9-jjhw-wwvq62 html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking63 https://osv.dev/vulnerability/EEF-CVE-2026-663706465 EEF-CVE-2026-66829 (LOW)66 aka: CVE-2026-66829, GHSA-2c6f-3j54-xpcr67 html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection68 https://osv.dev/vulnerability/EEF-CVE-2026-668296970 EEF-CVE-2026-66843 (LOW)71 aka: CVE-2026-66843, GHSA-xmm9-jc22-rcgj72 html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding73 https://osv.dev/vulnerability/EEF-CVE-2026-668437475 EEF-CVE-2026-68747 (LOW)76 aka: CVE-2026-68747, GHSA-87v2-pfhj-r5x777 CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input78 https://osv.dev/vulnerability/EEF-CVE-2026-687477980 EEF-CVE-2026-68750 (HIGH)81 aka: CVE-2026-68750, GHSA-463q-p2fr-mh9p82 Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service83 https://osv.dev/vulnerability/EEF-CVE-2026-6875084 httpoison 1.8.285 idna 6.1.186 interactive_cmd 0.1.487 jason 1.1.288 metrics 1.0.189 mime 2.0.790 mimerl 1.5.091 mochiweb 2.22.092 nerves 2.0.0-pre.293 nerves_discovery 0.1.594 nerves_logging 0.2.495 nerves_runtime 0.13.1396 nerves_system_bbb 2.30.297 nerves_system_br 1.34.498 nerves_system_mangopi_mq_pro 0.17.299 nerves_system_qemu_aarch64 0.4.2100 nerves_system_rpi0 2.1.2101 nerves_system_rpi4 2.1.2102 nerves_system_rpi5 2.1.2103 nerves_system_trellis 0.5.0104 nerves_system_x86_64 1.34.2105 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1106 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1107 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1108 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1109 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1110 nerves_uevent 0.1.7111 nimble_ownership 1.0.2112 parse_trans 3.4.1113 plug 1.20.3114 plug_cowboy 2.9.0115 plug_crypto 2.2.0116 postgrex 0.17.5 VULNERABLE!117 EEF-CVE-2026-32687 (HIGH)118 aka: CVE-2026-32687, GHSA-r73h-97w8-m54h119 SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3120 https://osv.dev/vulnerability/EEF-CVE-2026-32687121122 EEF-CVE-2026-58225 (LOW)123 aka: CVE-2026-58225, GHSA-4mw9-4qgj-m97w124 SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service125 https://osv.dev/vulnerability/EEF-CVE-2026-58225126 property_table 0.3.4127 ranch 2.3.0128 ring_logger 0.11.7129 ssl_verify_fun 1.1.7130 tablet 0.3.3131 telemetry 1.4.2132 toolshed 0.5.0133 uboot_env 1.0.2134 unicode_util_compat 0.7.1135Found packages with security advisories, see above for details136All dependencies have been fetched137==> html_entities138Compiling 2 files (.ex)139Generated html_entities app140==> nerves_compatibility_test141===> Analyzing applications...142===> Compiling mochiweb143 ┌─ src/mochinum.erl:144 │145 47 │ digits(0.0) ->146 │ ╰── Warning: matching on the float 0.0 will no longer also match -0.0 in OTP 27.147If you specifically intend to match 0.0 alone, write +0.0 instead.148149150 ┌─ src/mochiweb_util.erl:151 │152 143 │ after catch port_close(Port)153 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.154Compile directive 'nowarn_deprecated_catch' can be used to suppress155warnings in selected modules.156157158 ┌─ src/mochiweb_socket_server.erl:159 │160 199 │ case (catch inet:getaddr("localhost", inet6)) of161 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.162Compile directive 'nowarn_deprecated_catch' can be used to suppress163warnings in selected modules.164165 ┌─ src/mochiweb_socket_server.erl:166 │167 322 │ catch F([{timing, Timing} | state_to_proplist(State1)])168 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.169Compile directive 'nowarn_deprecated_catch' can be used to suppress170warnings in selected modules.171172173 ┌─ src/reloader.erl:174 │175 154 │ case catch Module:test() of176 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.177Compile directive 'nowarn_deprecated_catch' can be used to suppress178warnings in selected modules.179180181===> Compiling src/mochiweb_multipart.erl failed182 ┌─ src/mochiweb_multipart.erl:183 │184 278 │ {maybe, Start} ->185 │ ╰── syntax error before: ','186187 ┌─ src/mochiweb_multipart.erl:188 │189 331 │ {maybe, Skip};190 │ ╰── syntax error before: ','191192193 ┌─ src/mochiweb_multipart.erl:194 │195 186 │ feed_mp(headers,196 │ ╰── function feed_mp/2 undefined197198199 ┌─ src/mochiweb_multipart.erl:200 │201 191 │ parse_headers(<<>>) -> [];202 │ ╰── Warning: function parse_headers/1 is unused203204 ┌─ src/mochiweb_multipart.erl:205 │206 194 │ parse_headers(Binary, Acc) ->207 │ ╰── Warning: function parse_headers/2 is unused208209 ┌─ src/mochiweb_multipart.erl:210 │211 202 │ split_header(Line) ->212 │ ╰── Warning: function split_header/1 is unused213214 ┌─ src/mochiweb_multipart.erl:215 │216 217 │ read_more(State = #mp{length = Length, buffer = Buffer,217 │ ╰── Warning: function read_more/1 is unused218219 ┌─ src/mochiweb_multipart.erl:220 │221 300 │ find_in_binary(P, Data) when size(P) > 0 ->222 │ ╰── Warning: function find_in_binary/2 is unused223224 ┌─ src/mochiweb_multipart.erl:225 │226 312 │ partial_find(_B, _D, _N, 0) -> not_found;227 │ ╰── Warning: function partial_find/4 is unused228229230** (Mix) Could not compile dependency :mochiweb, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile mochiweb --force", update it with "mix deps.update mochiweb" or clean it with "mix deps.clean mochiweb"