fulib_absinthe

Build log

nerves_system_x86_64

fulib_absinthe 0.1.10 · fail · run fulib_absinthe-0.1.10-1791186217492
346 of 346 lines
1Resolving Hex dependencies...2Resolution completed in 0.673s3Unchanged:4  absinthe 1.12.05  absinthe_plug 1.5.106  certifi 2.15.07  circular_buffer 1.1.08  combine 0.10.09  cowboy 2.6.3 VULNERABLE!10    EEF-CVE-2026-8466 (HIGH)11    aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x812    Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy13    https://osv.dev/vulnerability/EEF-CVE-2026-84661415    EEF-CVE-2026-65624 (MEDIUM)16    aka: CVE-2026-6562417    Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion18    https://osv.dev/vulnerability/EEF-CVE-2026-656241920    GHSA-w4f7-4cxr-rv3c (MEDIUM)21    aka: CVE-2026-43966, EEF-CVE-2026-4396622    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability23    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c24  cowlib 2.7.3 VULNERABLE!25    EEF-CVE-2026-59248 (HIGH)26    aka: CVE-2026-5924827    Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS28    https://osv.dev/vulnerability/EEF-CVE-2026-592482930    EEF-CVE-2026-43970 (HIGH)31    aka: CVE-2026-43970, GHSA-84f2-rp86-235p32    Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame33    https://osv.dev/vulnerability/EEF-CVE-2026-439703435    EEF-CVE-2026-43968 (MEDIUM)36    aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r37    CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/138    https://osv.dev/vulnerability/EEF-CVE-2026-439683940    EEF-CVE-2026-7790 (HIGH)41    aka: CVE-2026-7790, GHSA-32p9-57cr-4x6542    Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS43    https://osv.dev/vulnerability/EEF-CVE-2026-779044  crc 0.11.045  dataloader 1.0.1146  db_connection 2.10.247  decimal 2.4.1 VULNERABLE!48    EEF-CVE-2026-32686 (MEDIUM)49    aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v50    Unbounded exponent in decimal enables unauthenticated DoS51    https://osv.dev/vulnerability/EEF-CVE-2026-3268652  decorator 1.4.053  earmark 1.4.49 RETIRED! VULNERABLE!54    (deprecated) Earmark is no longer maintained. Migrate to a replacement, for example MDEx (https://hex.pm/packages/mdex).5556    EEF-CVE-2026-48591 (MEDIUM)57    aka: CVE-2026-48591, GHSA-52mm-h59v-f3c758    Stored XSS via unescaped HTML attribute values in earmark59    https://osv.dev/vulnerability/EEF-CVE-2026-4859160  ecto 3.13.661  ecto_sql 3.13.562  elixir_make 0.10.063  ex_marshal 0.0.1364  expo 1.1.165  floki 0.38.466  fulib 0.1.1867  fulib_absinthe 0.1.1068  gen_stage 0.14.369  gettext 0.26.270  grpc 0.3.1 VULNERABLE!71    EEF-CVE-2026-48854 (HIGH)72    aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj73    Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc74    https://osv.dev/vulnerability/EEF-CVE-2026-4885475  gun 1.3.3 VULNERABLE!76    EEF-CVE-2026-43973 (HIGH)77    aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7778    gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion79    https://osv.dev/vulnerability/EEF-CVE-2026-439738081    GHSA-w4f7-4cxr-rv3c (MEDIUM)82    aka: CVE-2026-43966, EEF-CVE-2026-4396683    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability84    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c85  hackney 1.25.0 VULNERABLE!86    EEF-CVE-2026-47071 (HIGH)87    aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr88    SOCKS5 TLS upgrade ignores caller timeout in hackney89    https://osv.dev/vulnerability/EEF-CVE-2026-470719091    EEF-CVE-2026-47076 (MEDIUM)92    aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq93    SSRF allowlist bypass via percent-encoded host in hackney94    https://osv.dev/vulnerability/EEF-CVE-2026-470769596    EEF-CVE-2026-47069 (LOW)97    aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw298    CRLF injection in cookie domain/path options in hackney99    https://osv.dev/vulnerability/EEF-CVE-2026-47069100101    EEF-CVE-2026-47075 (MEDIUM)102    aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf103    CR/LF injection in query parameter in hackney104    https://osv.dev/vulnerability/EEF-CVE-2026-47075105  httpoison 1.8.2106  idna 6.1.1107  inet_cidr 1.0.9108  interactive_cmd 0.1.4109  jason 1.4.5110  jchash 0.1.4111  liquid 0.9.1112  logger_file_backend 0.1.1113  mbcs 1.1.1114  metrics 1.0.1115  mime 2.0.7116  mimerl 1.5.0117  nebulex 1.2.2118  nebulex_cluster 0.1.0119  nebulex_redis_adapter 1.1.1120  nerves 2.0.0-pre.2121  nerves_discovery 0.1.5122  nerves_logging 0.2.4123  nerves_runtime 0.13.13124  nerves_system_bbb 2.30.2125  nerves_system_br 1.34.4126  nerves_system_mangopi_mq_pro 0.17.2127  nerves_system_qemu_aarch64 0.4.2128  nerves_system_rpi0 2.1.2129  nerves_system_rpi4 2.1.2130  nerves_system_rpi5 2.1.2131  nerves_system_trellis 0.5.0132  nerves_system_x86_64 1.34.2133  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1134  nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1135  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1136  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1137  nerves_toolchain_x86_64_nerves_linux_musl 15.3.1138  nerves_uevent 0.1.7139  nimble_parsec 1.4.2140  parse_trans 3.4.1141  phoenix_html 2.14.3 VULNERABLE!142    GHSA-5g2h-9x5v-5h3x (MEDIUM)143    aka: CVE-2021-46871, GHSA-j3gg-r6gp-95q2144    phoenix_html allows Cross-site Scripting in HEEx class attributes145    https://osv.dev/vulnerability/GHSA-5g2h-9x5v-5h3x146  plug 1.20.3147  plug_cowboy 2.1.3 VULNERABLE!148    EEF-CVE-2026-32688 (HIGH)149    aka: CVE-2026-32688, GHSA-q8x4-x7mp-5vg2150    Atom table exhaustion via HTTP/2 :scheme pseudo-header in plug_cowboy151    https://osv.dev/vulnerability/EEF-CVE-2026-32688152  plug_crypto 2.2.0153  postgrex 0.22.4154  property_table 0.3.4155  protobuf 0.17.0156  ranch 1.7.1157  recase 0.9.1158  redix 0.11.2159  remote_ip 0.2.1160  ring_logger 0.11.7161  shards 0.6.2162  shorter_maps 2.2.5163  ssl_verify_fun 1.1.7164  tablet 0.3.3165  telemetry 0.4.3166  timex 3.7.13167  tiny_util 0.2.0168  toolshed 0.5.0169  tzdata 1.2.2170  uboot_env 1.0.2171  unicode_util_compat 0.7.1172  yamerl 0.10.0173* Getting fulib_absinthe (Hex package)174* Getting nerves (Hex package)175* Getting ring_logger (Hex package)176* Getting toolshed (Hex package)177* Getting nerves_runtime (Hex package)178* Getting nerves_system_bbb (Hex package)179* Getting nerves_system_mangopi_mq_pro (Hex package)180* Getting nerves_system_qemu_aarch64 (Hex package)181* Getting nerves_system_rpi0 (Hex package)182* Getting nerves_system_rpi4 (Hex package)183* Getting nerves_system_rpi5 (Hex package)184* Getting nerves_system_trellis (Hex package)185* Getting nerves_system_x86_64 (Hex package)186* Getting nerves_system_br (Hex package)187* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)188* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)189* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)190* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)191* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)192* Getting nerves_logging (Hex package)193* Getting nerves_uevent (Hex package)194* Getting uboot_env (Hex package)195* Getting elixir_make (Hex package)196* Getting property_table (Hex package)197* Getting circular_buffer (Hex package)198* Getting interactive_cmd (Hex package)199* Getting nerves_discovery (Hex package)200* Getting tablet (Hex package)201* Getting absinthe_plug (Hex package)202* Getting fulib (Hex package)203* Getting grpc (Hex package)204* Getting gun (Hex package)205* Getting postgrex (Hex package)206* Getting remote_ip (Hex package)207* Getting combine (Hex package)208* Getting inet_cidr (Hex package)209* Getting plug (Hex package)210* Getting mime (Hex package)211* Getting plug_crypto (Hex package)212* Getting telemetry (Hex package)213* Getting db_connection (Hex package)214* Getting decimal (Hex package)215* Getting cowlib (Hex package)216* Getting cowboy (Hex package)217* Getting protobuf (Hex package)218* Getting ranch (Hex package)219* Getting dataloader (Hex package)220* Getting earmark (Hex package)221* Getting ecto (Hex package)222* Getting ecto_sql (Hex package)223* Getting ex_marshal (Hex package)224* Getting floki (Hex package)225* Getting gen_stage (Hex package)226* Getting gettext (Hex package)227* Getting httpoison (Hex package)228* Getting jason (Hex package)229* Getting liquid (Hex package)230* Getting logger_file_backend (Hex package)231* Getting nebulex (Hex package)232* Getting nebulex_redis_adapter (Hex package)233* Getting phoenix_html (Hex package)234* Getting plug_cowboy (Hex package)235* Getting recase (Hex package)236* Getting shorter_maps (Hex package)237* Getting timex (Hex package)238* Getting tiny_util (Hex package)239* Getting yamerl (Hex package)240* Getting mbcs (Hex package)241* Getting tzdata (Hex package)242* Getting crc (Hex package)243* Getting jchash (Hex package)244* Getting nebulex_cluster (Hex package)245* Getting redix (Hex package)246* Getting decorator (Hex package)247* Getting shards (Hex package)248* Getting hackney (Hex package)249* Getting certifi (Hex package)250* Getting idna (Hex package)251* Getting metrics (Hex package)252* Getting mimerl (Hex package)253* Getting parse_trans (Hex package)254* Getting ssl_verify_fun (Hex package)255* Getting unicode_util_compat (Hex package)256* Getting expo (Hex package)257* Getting absinthe (Hex package)258* Getting nimble_parsec (Hex package)259Found retired packages, see above for details260Found packages with security advisories, see above for details261You have added/upgraded packages you could sponsor, run `mix hex.sponsor` to learn more262===> Analyzing applications...263===> Compiling ranch264     ┌─ src/ranch_ssl.erl:265     │266 142 │  	case ssl:ssl_accept(CSocket, Opts, Timeout) of267     │  	     ╰── Warning: ssl:ssl_accept/3 is removed; use ssl:handshake/1,2,3 instead268269270    ┌─ src/ranch_conns_sup.erl:271    │272 80 │  	catch erlang:send(SupPid, {?MODULE, active_connections, self(), Tag},273    │  	╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.274Compile directive 'nowarn_deprecated_catch' can be used to suppress275warnings in selected modules.276277278make: Entering directory '/work/proj/deps_x86_64/jchash/c_src'279/home/nerves/.nerves/artifacts/nerves_toolchain_x86_64_nerves_linux_musl-15.3.1/bin/x86_64-nerves-linux-musl-gcc -m64 -fstack-protector-strong -march=x86-64 -fPIE -pie -Wl,-z,now -Wl,-z,relro -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64  -pipe -O2 --sysroot /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging -O3 -std=c99 -finline-functions -Wall -Wmissing-prototypes -fPIC -I /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging/usr/lib/erlang/erts-17.0.6/include -I /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging/usr/lib/erlang/lib/erl_interface-5.8.2/include -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 --sysroot /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging -c -o /work/proj/deps_x86_64/jchash/c_src/jchash.o /work/proj/deps_x86_64/jchash/c_src/jchash.c280/home/nerves/.nerves/artifacts/nerves_toolchain_x86_64_nerves_linux_musl-15.3.1/bin/x86_64-nerves-linux-musl-gcc /work/proj/deps_x86_64/jchash/c_src/jchash.o --sysroot=/home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging -shared -L /home/nerves/.nerves/artifacts/nerves_system_x86_64-1.34.2/staging/usr/lib/erlang/lib/erl_interface-5.8.2/lib -lei -o /work/proj/deps_x86_64/jchash/c_src/../priv/jchash.so281make: Leaving directory '/work/proj/deps_x86_64/jchash/c_src'282===> Analyzing applications...283===> Compiling jchash284===> Fetching rebar3_hex v7.3.0285===> Fetching hex_core v0.19.0286===> Fetching verl v1.1.1287===> Analyzing applications...288===> Compiling verl289===> Compiling hex_core290===> Compiling rebar3_hex291===> Analyzing applications...292===> Compiling mbcs293===> Analyzing applications...294===> Compiling shards295     ┌─ src/shards_owner_sup.erl:296     │297 161 │    ok = pg2:create(Tab),298     │         ╰── Warning: pg2:create/1 is removed; this module was removed in OTP 24. Use 'pg' instead299300     ┌─ src/shards_owner_sup.erl:301     │302 162 │    ok = pg2:join(Tab, self());303     │         ╰── Warning: pg2:join/2 is removed; this module was removed in OTP 24. Use 'pg' instead304305306     ┌─ src/shards_dist.erl:307     │308 125 │    pg2:join(Tab, shards_lib:get_pid(Tab)).309     │    ╰── Warning: pg2:join/2 is removed; this module was removed in OTP 24. Use 'pg' instead310311     ┌─ src/shards_dist.erl:312     │313 130 │      Members = [{node(Pid), Pid} || Pid <- pg2:get_members(Tab)],314     │                                            ╰── Warning: pg2:get_members/1 is removed; this module was removed in OTP 24. Use 'pg' instead315316     ┌─ src/shards_dist.erl:317     │318 135 │            {Node, Pid} -> pg2:leave(Tab, Pid);319     │                           ╰── Warning: pg2:leave/2 is removed; this module was removed in OTP 24. Use 'pg' instead320321     ┌─ src/shards_dist.erl:322     │323 145 │    lists:usort([node(Pid) || Pid <- pg2:get_members(Tab)]).324     │                                     ╰── Warning: pg2:get_members/1 is removed; this module was removed in OTP 24. Use 'pg' instead325326     ┌─ src/shards_dist.erl:327     │328 440 │    ok = pg2:delete(Tab),329     │         ╰── Warning: pg2:delete/1 is removed; this module was removed in OTP 24. Use 'pg' instead330331     ┌─ src/shards_dist.erl:332     │333 441 │    ok = pg2:create(Name),334     │         ╰── Warning: pg2:create/1 is removed; this module was removed in OTP 24. Use 'pg' instead335336337===> Analyzing applications...338===> Compiling cowlib339===> Compiling src/cow_sse.erl failed340    ┌─ src/cow_sse.erl:341    │342 56 │  	-> {event, parsed_event(), State} | {more, State}.343    │  	                           ╰── type variable 'State' is only used once (is unbound)344345346** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/x86_64/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"