Build log
nerves_system_x86_64
fulib_absinthe 0.1.10 · fail · run fulib_absinthe-0.1.10-1791186217492
346 of 346 lines
1Resolving Hex dependencies...2Resolution completed in 0.673s3Unchanged:4 absinthe 1.12.05 absinthe_plug 1.5.106 certifi 2.15.07 circular_buffer 1.1.08 combine 0.10.09 cowboy 2.6.3 VULNERABLE!10 EEF-CVE-2026-8466 (HIGH)11 aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x812 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy13 https://osv.dev/vulnerability/EEF-CVE-2026-84661415 EEF-CVE-2026-65624 (MEDIUM)16 aka: CVE-2026-6562417 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion18 https://osv.dev/vulnerability/EEF-CVE-2026-656241920 GHSA-w4f7-4cxr-rv3c (MEDIUM)21 aka: CVE-2026-43966, EEF-CVE-2026-4396622 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability23 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c24 cowlib 2.7.3 VULNERABLE!25 EEF-CVE-2026-59248 (HIGH)26 aka: CVE-2026-5924827 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS28 https://osv.dev/vulnerability/EEF-CVE-2026-592482930 EEF-CVE-2026-43970 (HIGH)31 aka: CVE-2026-43970, GHSA-84f2-rp86-235p32 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame33 https://osv.dev/vulnerability/EEF-CVE-2026-439703435 EEF-CVE-2026-43968 (MEDIUM)36 aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r37 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/138 https://osv.dev/vulnerability/EEF-CVE-2026-439683940 EEF-CVE-2026-7790 (HIGH)41 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6542 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS43 https://osv.dev/vulnerability/EEF-CVE-2026-779044 crc 0.11.045 dataloader 1.0.1146 db_connection 2.10.247 decimal 2.4.1 VULNERABLE!48 EEF-CVE-2026-32686 (MEDIUM)49 aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v50 Unbounded exponent in decimal enables unauthenticated DoS51 https://osv.dev/vulnerability/EEF-CVE-2026-3268652 decorator 1.4.053 earmark 1.4.49 RETIRED! VULNERABLE!54 (deprecated) Earmark is no longer maintained. Migrate to a replacement, for example MDEx (https://hex.pm/packages/mdex).5556 EEF-CVE-2026-48591 (MEDIUM)57 aka: CVE-2026-48591, GHSA-52mm-h59v-f3c758 Stored XSS via unescaped HTML attribute values in earmark59 https://osv.dev/vulnerability/EEF-CVE-2026-4859160 ecto 3.13.661 ecto_sql 3.13.562 elixir_make 0.10.063 ex_marshal 0.0.1364 expo 1.1.165 floki 0.38.466 fulib 0.1.1867 fulib_absinthe 0.1.1068 gen_stage 0.14.369 gettext 0.26.270 grpc 0.3.1 VULNERABLE!71 EEF-CVE-2026-48854 (HIGH)72 aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj73 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc74 https://osv.dev/vulnerability/EEF-CVE-2026-4885475 gun 1.3.3 VULNERABLE!76 EEF-CVE-2026-43973 (HIGH)77 aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7778 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion79 https://osv.dev/vulnerability/EEF-CVE-2026-439738081 GHSA-w4f7-4cxr-rv3c (MEDIUM)82 aka: CVE-2026-43966, EEF-CVE-2026-4396683 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability84 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c85 hackney 1.25.0 VULNERABLE!86 EEF-CVE-2026-47071 (HIGH)87 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr88 SOCKS5 TLS upgrade ignores caller timeout in hackney89 https://osv.dev/vulnerability/EEF-CVE-2026-470719091 EEF-CVE-2026-47076 (MEDIUM)92 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq93 SSRF allowlist bypass via percent-encoded host in hackney94 https://osv.dev/vulnerability/EEF-CVE-2026-470769596 EEF-CVE-2026-47069 (LOW)97 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw298 CRLF injection in cookie domain/path options in hackney99 https://osv.dev/vulnerability/EEF-CVE-2026-47069100101 EEF-CVE-2026-47075 (MEDIUM)102 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf103 CR/LF injection in query parameter in hackney104 https://osv.dev/vulnerability/EEF-CVE-2026-47075105 httpoison 1.8.2106 idna 6.1.1107 inet_cidr 1.0.9108 interactive_cmd 0.1.4109 jason 1.4.5110 jchash 0.1.4111 liquid 0.9.1112 logger_file_backend 0.1.1113 mbcs 1.1.1114 metrics 1.0.1115 mime 2.0.7116 mimerl 1.5.0117 nebulex 1.2.2118 nebulex_cluster 0.1.0119 nebulex_redis_adapter 1.1.1120 nerves 2.0.0-pre.2121 nerves_discovery 0.1.5122 nerves_logging 0.2.4123 nerves_runtime 0.13.13124 nerves_system_bbb 2.30.2125 nerves_system_br 1.34.4126 nerves_system_mangopi_mq_pro 0.17.2127 nerves_system_qemu_aarch64 0.4.2128 nerves_system_rpi0 2.1.2129 nerves_system_rpi4 2.1.2130 nerves_system_rpi5 2.1.2131 nerves_system_trellis 0.5.0132 nerves_system_x86_64 1.34.2133 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1134 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1135 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1136 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1137 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1138 nerves_uevent 0.1.7139 nimble_parsec 1.4.2140 parse_trans 3.4.1141 phoenix_html 2.14.3 VULNERABLE!142 GHSA-5g2h-9x5v-5h3x (MEDIUM)143 aka: CVE-2021-46871, GHSA-j3gg-r6gp-95q2144 phoenix_html allows Cross-site Scripting in HEEx class attributes145 https://osv.dev/vulnerability/GHSA-5g2h-9x5v-5h3x146 plug 1.20.3147 plug_cowboy 2.1.3 VULNERABLE!148 EEF-CVE-2026-32688 (HIGH)149 aka: CVE-2026-32688, GHSA-q8x4-x7mp-5vg2150 Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy151 https://osv.dev/vulnerability/EEF-CVE-2026-32688152 plug_crypto 2.2.0153 postgrex 0.22.4154 property_table 0.3.4155 protobuf 0.17.0156 ranch 1.7.1157 recase 0.9.1158 redix 0.11.2159 remote_ip 0.2.1160 ring_logger 0.11.7161 shards 0.6.2162 shorter_maps 2.2.5163 ssl_verify_fun 1.1.7164 tablet 0.3.3165 telemetry 0.4.3166 timex 3.7.13167 tiny_util 0.2.0168 toolshed 0.5.0169 tzdata 1.2.2170 uboot_env 1.0.2171 unicode_util_compat 0.7.1172 yamerl 0.10.0173* Getting fulib_absinthe (Hex package)174* Getting nerves (Hex package)175* Getting ring_logger (Hex package)176* Getting toolshed (Hex package)177* Getting nerves_runtime (Hex package)178* Getting nerves_system_bbb (Hex package)179* Getting nerves_system_mangopi_mq_pro (Hex package)180* Getting nerves_system_qemu_aarch64 (Hex package)181* Getting nerves_system_rpi0 (Hex package)182* Getting nerves_system_rpi4 (Hex package)183* Getting nerves_system_rpi5 (Hex package)184* Getting nerves_system_trellis (Hex package)185* Getting nerves_system_x86_64 (Hex package)186* Getting nerves_system_br (Hex package)187* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)188* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)189* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)190* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)191* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)192* Getting nerves_logging (Hex package)193* Getting nerves_uevent (Hex package)194* Getting uboot_env (Hex package)195* Getting elixir_make (Hex package)196* Getting property_table (Hex package)197* Getting circular_buffer (Hex package)198* Getting interactive_cmd (Hex package)199* Getting nerves_discovery (Hex package)200* Getting tablet (Hex package)201* Getting absinthe_plug (Hex package)202* Getting fulib (Hex package)203* Getting grpc (Hex package)204* Getting gun (Hex package)205* Getting postgrex (Hex package)206* Getting remote_ip (Hex package)207* Getting combine (Hex package)208* Getting inet_cidr (Hex package)209* Getting plug (Hex package)210* Getting mime (Hex package)211* Getting plug_crypto (Hex package)212* Getting telemetry (Hex package)213* Getting db_connection (Hex package)214* Getting decimal (Hex package)215* Getting cowlib (Hex package)216* Getting cowboy (Hex package)217* Getting protobuf (Hex package)218* Getting ranch (Hex package)219* Getting dataloader (Hex package)220* Getting earmark (Hex package)221* Getting ecto (Hex package)222* Getting ecto_sql (Hex package)223* Getting ex_marshal (Hex package)224* Getting floki (Hex package)225* Getting gen_stage (Hex package)226* Getting gettext (Hex package)227* Getting httpoison (Hex package)228* Getting jason (Hex package)229* Getting liquid (Hex package)230* Getting logger_file_backend (Hex package)231* Getting nebulex (Hex package)232* Getting nebulex_redis_adapter (Hex package)233* Getting phoenix_html (Hex package)234* Getting plug_cowboy (Hex package)235* Getting recase (Hex package)236* Getting shorter_maps (Hex package)237* Getting timex (Hex package)238* Getting tiny_util (Hex package)239* Getting yamerl (Hex package)240* Getting mbcs (Hex package)241* Getting tzdata (Hex package)242* Getting crc (Hex package)243* Getting jchash (Hex package)244* Getting nebulex_cluster (Hex package)245* Getting redix (Hex package)246* Getting decorator (Hex package)247* Getting shards (Hex package)248* Getting hackney (Hex package)249* Getting certifi (Hex package)250* Getting idna (Hex package)251* Getting metrics (Hex package)252* Getting mimerl (Hex package)253* Getting parse_trans (Hex package)254* Getting ssl_verify_fun (Hex package)255* Getting unicode_util_compat (Hex package)256* Getting expo (Hex package)257* Getting absinthe (Hex package)258* Getting nimble_parsec (Hex package)259Found retired packages, see above for details260Found packages with security advisories, see above for details261You have added/upgraded packages you could sponsor, run `mix hex.sponsor` to learn more262===> Analyzing applications...263===> Compiling ranch264 ┌─ src/ranch_ssl.erl:265 │266 142 │ case ssl:ssl_accept(CSocket, Opts, Timeout) of267 │ ╰── Warning: ssl:ssl_accept/3 is removed; use ssl:handshake/1,2,3 instead268269270 ┌─ src/ranch_conns_sup.erl:271 │272 80 │ catch erlang:send(SupPid, {?MODULE, active_connections, self(), Tag},273 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.274Compile directive 'nowarn_deprecated_catch' can be used to suppress275warnings in selected modules.276277278make: Entering directory '/work/proj/deps_x86_64/jchash/c_src'279/home/nerves/.nerves/artifacts/nerves_toolchain_x86_64_nerves_linux_musl-15.3.1/bin/x86_64-nerves-linux-musl-gcc -m64 -fstack-protector-strong -march=x86-64 -fPIE -pie -Wl,-z,now -Wl,-z,relro -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -pipe -O2 --sysroot /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging -O3 -std=c99 -finline-functions -Wall -Wmissing-prototypes -fPIC -I /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging/usr/lib/erlang/erts-17.0.6/include -I /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging/usr/lib/erlang/lib/erl_interface-5.8.2/include -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 --sysroot /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging -c -o /work/proj/deps_x86_64/jchash/c_src/jchash.o /work/proj/deps_x86_64/jchash/c_src/jchash.c280/home/nerves/.nerves/artifacts/nerves_toolchain_x86_64_nerves_linux_musl-15.3.1/bin/x86_64-nerves-linux-musl-gcc /work/proj/deps_x86_64/jchash/c_src/jchash.o --sysroot=/home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging -shared -L /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging/usr/lib/erlang/lib/erl_interface-5.8.2/lib -lei -o /work/proj/deps_x86_64/jchash/c_src/../priv/jchash.so281make: Leaving directory '/work/proj/deps_x86_64/jchash/c_src'282===> Analyzing applications...283===> Compiling jchash284===> Fetching rebar3_hex v7.3.0285===> Fetching hex_core v0.19.0286===> Fetching verl v1.1.1287===> Analyzing applications...288===> Compiling verl289===> Compiling hex_core290===> Compiling rebar3_hex291===> Analyzing applications...292===> Compiling mbcs293===> Analyzing applications...294===> Compiling shards295 ┌─ src/shards_owner_sup.erl:296 │297 161 │ ok = pg2:create(Tab),298 │ ╰── Warning: pg2:create/1 is removed; this module was removed in OTP 24. Use 'pg' instead299300 ┌─ src/shards_owner_sup.erl:301 │302 162 │ ok = pg2:join(Tab, self());303 │ ╰── Warning: pg2:join/2 is removed; this module was removed in OTP 24. Use 'pg' instead304305306 ┌─ src/shards_dist.erl:307 │308 125 │ pg2:join(Tab, shards_lib:get_pid(Tab)).309 │ ╰── Warning: pg2:join/2 is removed; this module was removed in OTP 24. Use 'pg' instead310311 ┌─ src/shards_dist.erl:312 │313 130 │ Members = [{node(Pid), Pid} || Pid <- pg2:get_members(Tab)],314 │ ╰── Warning: pg2:get_members/1 is removed; this module was removed in OTP 24. Use 'pg' instead315316 ┌─ src/shards_dist.erl:317 │318 135 │ {Node, Pid} -> pg2:leave(Tab, Pid);319 │ ╰── Warning: pg2:leave/2 is removed; this module was removed in OTP 24. Use 'pg' instead320321 ┌─ src/shards_dist.erl:322 │323 145 │ lists:usort([node(Pid) || Pid <- pg2:get_members(Tab)]).324 │ ╰── Warning: pg2:get_members/1 is removed; this module was removed in OTP 24. Use 'pg' instead325326 ┌─ src/shards_dist.erl:327 │328 440 │ ok = pg2:delete(Tab),329 │ ╰── Warning: pg2:delete/1 is removed; this module was removed in OTP 24. Use 'pg' instead330331 ┌─ src/shards_dist.erl:332 │333 441 │ ok = pg2:create(Name),334 │ ╰── Warning: pg2:create/1 is removed; this module was removed in OTP 24. Use 'pg' instead335336337===> Analyzing applications...338===> Compiling cowlib339===> Compiling src/cow_sse.erl failed340 ┌─ src/cow_sse.erl:341 │342 56 │ -> {event, parsed_event(), State} | {more, State}.343 │ ╰── type variable 'State' is only used once (is unbound)344345346** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/x86_64/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"