fluminus_bot

Build log

host

fluminus_bot 0.1.0 · fail · run fluminus_bot-0.1.0-1791185280999
230 of 230 lines
1Resolving Hex dependencies...2Resolution completed in 0.313s3Unchanged:4  certifi 2.15.05  circular_buffer 1.1.06  cookie 0.1.27  cowboy 2.19.08  cowboy_telemetry 0.4.09  cowlib 2.20.0 VULNERABLE!10    EEF-CVE-2026-43966 (MEDIUM)11    aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c12    HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/213    https://osv.dev/vulnerability/EEF-CVE-2026-439661415    EEF-CVE-2026-43969 (LOW)16    aka: CVE-2026-43969, GHSA-g2wm-735q-3f5617    Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/118    https://osv.dev/vulnerability/EEF-CVE-2026-4396919  db_connection 2.10.220  decimal 1.9.0 VULNERABLE!21    EEF-CVE-2026-32686 (MEDIUM)22    aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v23    Unbounded exponent in decimal enables unauthenticated DoS24    https://osv.dev/vulnerability/EEF-CVE-2026-3268625  ecto 3.10.326  ecto_sql 3.10.227  elixir_make 0.10.028  ex_gram 0.71.029  ffmpex 0.6.030  floki 0.22.031  fluminus 1.4.332  fluminus_bot 0.1.033  hackney 1.25.0 VULNERABLE!34    EEF-CVE-2026-47071 (HIGH)35    aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr36    SOCKS5 TLS upgrade ignores caller timeout in hackney37    https://osv.dev/vulnerability/EEF-CVE-2026-470713839    EEF-CVE-2026-47076 (MEDIUM)40    aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq41    SSRF allowlist bypass via percent-encoded host in hackney42    https://osv.dev/vulnerability/EEF-CVE-2026-470764344    EEF-CVE-2026-47069 (LOW)45    aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw246    CRLF injection in cookie domain/path options in hackney47    https://osv.dev/vulnerability/EEF-CVE-2026-470694849    EEF-CVE-2026-47075 (MEDIUM)50    aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf51    CR/LF injection in query parameter in hackney52    https://osv.dev/vulnerability/EEF-CVE-2026-4707553  html_entities 0.4.054  html_sanitize_ex 1.3.0 VULNERABLE!55    EEF-CVE-2026-68749 (HIGH)56    aka: CVE-2026-68749, GHSA-4cx2-987x-rr2x57    Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service58    https://osv.dev/vulnerability/EEF-CVE-2026-687495960    EEF-CVE-2026-66370 (MEDIUM)61    aka: CVE-2026-66370, GHSA-w3f9-jjhw-wwvq62    html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking63    https://osv.dev/vulnerability/EEF-CVE-2026-663706465    EEF-CVE-2026-66829 (LOW)66    aka: CVE-2026-66829, GHSA-2c6f-3j54-xpcr67    html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection68    https://osv.dev/vulnerability/EEF-CVE-2026-668296970    EEF-CVE-2026-66843 (LOW)71    aka: CVE-2026-66843, GHSA-xmm9-jc22-rcgj72    html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding73    https://osv.dev/vulnerability/EEF-CVE-2026-668437475    EEF-CVE-2026-68747 (LOW)76    aka: CVE-2026-68747, GHSA-87v2-pfhj-r5x777    CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input78    https://osv.dev/vulnerability/EEF-CVE-2026-687477980    EEF-CVE-2026-68750 (HIGH)81    aka: CVE-2026-68750, GHSA-463q-p2fr-mh9p82    Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service83    https://osv.dev/vulnerability/EEF-CVE-2026-6875084  httpoison 1.8.285  idna 6.1.186  interactive_cmd 0.1.487  jason 1.1.288  metrics 1.0.189  mime 2.0.790  mimerl 1.5.091  mochiweb 2.22.092  nerves 2.0.0-pre.293  nerves_discovery 0.1.594  nerves_logging 0.2.495  nerves_runtime 0.13.1396  nerves_system_bbb 2.30.297  nerves_system_br 1.34.498  nerves_system_mangopi_mq_pro 0.17.299  nerves_system_qemu_aarch64 0.4.2100  nerves_system_rpi0 2.1.2101  nerves_system_rpi4 2.1.2102  nerves_system_rpi5 2.1.2103  nerves_system_trellis 0.5.0104  nerves_system_x86_64 1.34.2105  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1106  nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1107  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1108  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1109  nerves_toolchain_x86_64_nerves_linux_musl 15.3.1110  nerves_uevent 0.1.7111  nimble_ownership 1.0.2112  parse_trans 3.4.1113  plug 1.20.3114  plug_cowboy 2.9.0115  plug_crypto 2.2.0116  postgrex 0.17.5 VULNERABLE!117    EEF-CVE-2026-32687 (HIGH)118    aka: CVE-2026-32687, GHSA-r73h-97w8-m54h119    SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3120    https://osv.dev/vulnerability/EEF-CVE-2026-32687121122    EEF-CVE-2026-58225 (LOW)123    aka: CVE-2026-58225, GHSA-4mw9-4qgj-m97w124    SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service125    https://osv.dev/vulnerability/EEF-CVE-2026-58225126  property_table 0.3.4127  ranch 2.3.0128  ring_logger 0.11.7129  ssl_verify_fun 1.1.7130  tablet 0.3.3131  telemetry 1.4.2132  toolshed 0.5.0133  uboot_env 1.0.2134  unicode_util_compat 0.7.1135Found packages with security advisories, see above for details136All dependencies have been fetched137==> html_entities138Compiling 2 files (.ex)139Generated html_entities app140==> nerves_compatibility_test141===> Analyzing applications...142===> Compiling mochiweb143    ┌─ src/mochinum.erl:144    │145 47 │  digits(0.0) ->146    │         ╰── Warning: matching on the float 0.0 will no longer also match -0.0 in OTP 27.147If you specifically intend to match 0.0 alone, write +0.0 instead.148149150     ┌─ src/mochiweb_util.erl:151     │152 143 │      after catch port_close(Port)153     │            ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.154Compile directive 'nowarn_deprecated_catch' can be used to suppress155warnings in selected modules.156157158     ┌─ src/mochiweb_socket_server.erl:159     │160 199 │      case (catch inet:getaddr("localhost", inet6)) of161     │            ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.162Compile directive 'nowarn_deprecated_catch' can be used to suppress163warnings in selected modules.164165     ┌─ src/mochiweb_socket_server.erl:166     │167 322 │              catch F([{timing, Timing} | state_to_proplist(State1)])168     │              ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.169Compile directive 'nowarn_deprecated_catch' can be used to suppress170warnings in selected modules.171172173     ┌─ src/reloader.erl:174     │175 154 │                      case catch Module:test() of176     │                           ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.177Compile directive 'nowarn_deprecated_catch' can be used to suppress178warnings in selected modules.179180181===> Compiling src/mochiweb_multipart.erl failed182     ┌─ src/mochiweb_multipart.erl:183     │184 278 │        {maybe, Start} ->185     │              ╰── syntax error before: ','186187     ┌─ src/mochiweb_multipart.erl:188     │189 331 │  		{maybe, Skip};190     │  		      ╰── syntax error before: ','191192193     ┌─ src/mochiweb_multipart.erl:194     │195 186 │      feed_mp(headers,196     │      ╰── function feed_mp/2 undefined197198199     ┌─ src/mochiweb_multipart.erl:200     │201 191 │  parse_headers(<<>>) -> [];202     │  ╰── Warning: function parse_headers/1 is unused203204     ┌─ src/mochiweb_multipart.erl:205     │206 194 │  parse_headers(Binary, Acc) ->207     │  ╰── Warning: function parse_headers/2 is unused208209     ┌─ src/mochiweb_multipart.erl:210     │211 202 │  split_header(Line) ->212     │  ╰── Warning: function split_header/1 is unused213214     ┌─ src/mochiweb_multipart.erl:215     │216 217 │  read_more(State = #mp{length = Length, buffer = Buffer,217     │  ╰── Warning: function read_more/1 is unused218219     ┌─ src/mochiweb_multipart.erl:220     │221 300 │  find_in_binary(P, Data) when size(P) > 0 ->222     │  ╰── Warning: function find_in_binary/2 is unused223224     ┌─ src/mochiweb_multipart.erl:225     │226 312 │  partial_find(_B, _D, _N, 0) -> not_found;227     │  ╰── Warning: function partial_find/4 is unused228229230** (Mix) Could not compile dependency :mochiweb, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile mochiweb --force", update it with "mix deps.update mochiweb" or clean it with "mix deps.clean mochiweb"