Build log
nerves_system_x86_64
google_pubsub_grpc 0.2.1-beta.1 · fail · run google_pubsub_grpc-0.2.1-beta.1-1791190504542
190 of 190 lines
1Resolving Hex dependencies...2Resolution completed in 0.283s3Unchanged:4 certifi 2.15.05 circular_buffer 1.1.06 cowboy 2.7.0 VULNERABLE!7 EEF-CVE-2026-65624 (MEDIUM)8 aka: CVE-2026-656249 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion10 https://osv.dev/vulnerability/EEF-CVE-2026-656241112 EEF-CVE-2026-8466 (HIGH)13 aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x814 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy15 https://osv.dev/vulnerability/EEF-CVE-2026-84661617 GHSA-w4f7-4cxr-rv3c (MEDIUM)18 aka: CVE-2026-43966, EEF-CVE-2026-4396619 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability20 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c21 cowlib 2.8.0 VULNERABLE!22 EEF-CVE-2026-7790 (HIGH)23 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6524 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS25 https://osv.dev/vulnerability/EEF-CVE-2026-77902627 EEF-CVE-2026-43968 (MEDIUM)28 aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r29 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/130 https://osv.dev/vulnerability/EEF-CVE-2026-439683132 EEF-CVE-2026-59248 (HIGH)33 aka: CVE-2026-5924834 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS35 https://osv.dev/vulnerability/EEF-CVE-2026-592483637 EEF-CVE-2026-43970 (HIGH)38 aka: CVE-2026-43970, GHSA-84f2-rp86-235p39 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame40 https://osv.dev/vulnerability/EEF-CVE-2026-4397041 elixir_make 0.10.042 google_pubsub_grpc 0.2.1-beta.143 goth 1.2.044 grpc 0.5.0-beta.1 VULNERABLE!45 EEF-CVE-2026-53430 (HIGH)46 aka: CVE-2026-53430, GHSA-6ccx-9c9f-327w47 grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/148 https://osv.dev/vulnerability/EEF-CVE-2026-534304950 EEF-CVE-2026-48853 (CRITICAL)51 aka: CVE-2026-48853, GHSA-grp7-v8xh-rj7h52 Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc53 https://osv.dev/vulnerability/EEF-CVE-2026-488535455 EEF-CVE-2026-48854 (HIGH)56 aka: CVE-2026-48854, GHSA-q8gf-9rvj-gmgj57 Unbounded request body accumulation causes memory exhaustion in elixir-grpc/grpc58 https://osv.dev/vulnerability/EEF-CVE-2026-4885459 grpc_gun 2.0.060 hackney 1.25.0 VULNERABLE!61 EEF-CVE-2026-47071 (HIGH)62 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr63 SOCKS5 TLS upgrade ignores caller timeout in hackney64 https://osv.dev/vulnerability/EEF-CVE-2026-470716566 EEF-CVE-2026-47076 (MEDIUM)67 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq68 SSRF allowlist bypass via percent-encoded host in hackney69 https://osv.dev/vulnerability/EEF-CVE-2026-470767071 EEF-CVE-2026-47069 (LOW)72 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw273 CRLF injection in cookie domain/path options in hackney74 https://osv.dev/vulnerability/EEF-CVE-2026-470697576 EEF-CVE-2026-47075 (MEDIUM)77 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf78 CR/LF injection in query parameter in hackney79 https://osv.dev/vulnerability/EEF-CVE-2026-4707580 httpoison 1.8.281 idna 6.1.182 interactive_cmd 0.1.483 jason 1.4.584 joken 2.7.085 jose 1.11.1286 metrics 1.0.187 mimerl 1.5.088 nerves 2.0.0-pre.289 nerves_discovery 0.1.590 nerves_logging 0.2.491 nerves_runtime 0.13.1392 nerves_system_bbb 2.30.293 nerves_system_br 1.34.494 nerves_system_mangopi_mq_pro 0.17.295 nerves_system_qemu_aarch64 0.4.296 nerves_system_rpi0 2.1.297 nerves_system_rpi4 2.1.298 nerves_system_rpi5 2.1.299 nerves_system_trellis 0.5.0100 nerves_system_x86_64 1.34.2101 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1102 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1103 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1104 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1105 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1106 nerves_uevent 0.1.7107 parse_trans 3.4.1108 property_table 0.3.4109 protobuf 0.17.0110 ranch 1.7.1111 ring_logger 0.11.7112 ssl_verify_fun 1.1.7113 tablet 0.3.3114 toolshed 0.5.0115 uboot_env 1.0.2116 unicode_util_compat 0.7.1117* Getting google_pubsub_grpc (Hex package)118* Getting nerves (Hex package)119* Getting ring_logger (Hex package)120* Getting toolshed (Hex package)121* Getting nerves_runtime (Hex package)122* Getting nerves_system_bbb (Hex package)123* Getting nerves_system_mangopi_mq_pro (Hex package)124* Getting nerves_system_qemu_aarch64 (Hex package)125* Getting nerves_system_rpi0 (Hex package)126* Getting nerves_system_rpi4 (Hex package)127* Getting nerves_system_rpi5 (Hex package)128* Getting nerves_system_trellis (Hex package)129* Getting nerves_system_x86_64 (Hex package)130* Getting nerves_system_br (Hex package)131* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)132* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)133* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)134* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)135* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)136* Getting nerves_logging (Hex package)137* Getting nerves_uevent (Hex package)138* Getting uboot_env (Hex package)139* Getting elixir_make (Hex package)140* Getting property_table (Hex package)141* Getting circular_buffer (Hex package)142* Getting interactive_cmd (Hex package)143* Getting nerves_discovery (Hex package)144* Getting tablet (Hex package)145* Getting cowboy (Hex package)146* Getting goth (Hex package)147* Getting grpc (Hex package)148* Getting gun (Hex package)149* Getting protobuf (Hex package)150* Getting cowlib (Hex package)151* Getting httpoison (Hex package)152* Getting jason (Hex package)153* Getting joken (Hex package)154* Getting jose (Hex package)155* Getting hackney (Hex package)156* Getting certifi (Hex package)157* Getting idna (Hex package)158* Getting metrics (Hex package)159* Getting mimerl (Hex package)160* Getting parse_trans (Hex package)161* Getting ssl_verify_fun (Hex package)162* Getting unicode_util_compat (Hex package)163* Getting ranch (Hex package)164Found packages with security advisories, see above for details165===> Analyzing applications...166===> Compiling ranch167 ┌─ src/ranch_ssl.erl:168 │169 142 │ case ssl:ssl_accept(CSocket, Opts, Timeout) of170 │ ╰── Warning: ssl:ssl_accept/3 is removed; use ssl:handshake/1,2,3 instead171172173 ┌─ src/ranch_conns_sup.erl:174 │175 80 │ catch erlang:send(SupPid, {?MODULE, active_connections, self(), Tag},176 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.177Compile directive 'nowarn_deprecated_catch' can be used to suppress178warnings in selected modules.179180181===> Analyzing applications...182===> Compiling cowlib183===> Compiling src/cow_sse.erl failed184 ┌─ src/cow_sse.erl:185 │186 56 │ -> {event, parsed_event(), State} | {more, State}.187 │ ╰── type variable 'State' is only used once (is unbound)188189190** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/x86_64/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"