Build log
host
helix 0.1.6-rc · fail · run helix-0.1.6-rc-1791193982326
228 of 228 lines
1Resolving Hex dependencies...2Resolution completed in 0.832s3Unchanged:4 castore 1.0.215 certifi 2.15.06 circular_buffer 1.1.07 colour_hash 1.0.38 cowboy 2.9.0 VULNERABLE!9 EEF-CVE-2026-8466 (HIGH)10 aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x811 Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy12 https://osv.dev/vulnerability/EEF-CVE-2026-84661314 GHSA-w4f7-4cxr-rv3c (MEDIUM)15 aka: CVE-2026-43966, EEF-CVE-2026-4396616 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability17 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c1819 EEF-CVE-2026-65624 (MEDIUM)20 aka: CVE-2026-6562421 Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion22 https://osv.dev/vulnerability/EEF-CVE-2026-6562423 cowboy_telemetry 0.4.024 cowlib 2.11.0 VULNERABLE!25 EEF-CVE-2026-7790 (HIGH)26 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6527 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS28 https://osv.dev/vulnerability/EEF-CVE-2026-77902930 EEF-CVE-2026-43968 (MEDIUM)31 aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r32 CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/133 https://osv.dev/vulnerability/EEF-CVE-2026-439683435 EEF-CVE-2026-43970 (HIGH)36 aka: CVE-2026-43970, GHSA-84f2-rp86-235p37 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame38 https://osv.dev/vulnerability/EEF-CVE-2026-439703940 EEF-CVE-2026-59248 (HIGH)41 aka: CVE-2026-5924842 Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS43 https://osv.dev/vulnerability/EEF-CVE-2026-592484445 EEF-CVE-2026-43969 (LOW)46 aka: CVE-2026-43969, GHSA-g2wm-735q-3f5647 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/148 https://osv.dev/vulnerability/EEF-CVE-2026-439694950 EEF-CVE-2026-43966 (MEDIUM)51 aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c52 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/253 https://osv.dev/vulnerability/EEF-CVE-2026-439665455 EEF-CVE-2026-43971 (MEDIUM)56 aka: CVE-2026-4397157 Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/158 https://osv.dev/vulnerability/EEF-CVE-2026-4397159 db_connection 2.10.260 decimal 3.1.161 dotx 0.3.162 ecto 3.14.263 ecto_sql 3.14.064 elixir_make 0.10.065 esbuild 0.10.066 expo 1.1.167 file_system 1.1.168 floki 0.38.469 gettext 0.26.270 gun 2.0.0-rc.2 VULNERABLE!71 EEF-CVE-2026-43973 (HIGH)72 aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7773 gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion74 https://osv.dev/vulnerability/EEF-CVE-2026-439737576 GHSA-w4f7-4cxr-rv3c (MEDIUM)77 aka: CVE-2026-43966, EEF-CVE-2026-4396678 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability79 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c80 hackney 1.25.0 VULNERABLE!81 EEF-CVE-2026-47071 (HIGH)82 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr83 SOCKS5 TLS upgrade ignores caller timeout in hackney84 https://osv.dev/vulnerability/EEF-CVE-2026-470718586 EEF-CVE-2026-47076 (MEDIUM)87 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq88 SSRF allowlist bypass via percent-encoded host in hackney89 https://osv.dev/vulnerability/EEF-CVE-2026-470769091 EEF-CVE-2026-47069 (LOW)92 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw293 CRLF injection in cookie domain/path options in hackney94 https://osv.dev/vulnerability/EEF-CVE-2026-470699596 EEF-CVE-2026-47075 (MEDIUM)97 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf98 CR/LF injection in query parameter in hackney99 https://osv.dev/vulnerability/EEF-CVE-2026-47075100 helix 0.1.6-rc101 httpoison 1.8.2102 idna 6.1.1103 interactive_cmd 0.1.4104 jason 1.4.5105 json 1.4.1106 meck 0.9.2107 metrics 1.0.1108 mime 2.0.7109 mimerl 1.5.0110 mix_test_watch 1.4.0111 mock 0.3.9112 nerves 2.0.0-pre.2113 nerves_discovery 0.1.5114 nerves_logging 0.2.4115 nerves_runtime 0.13.13116 nerves_system_bbb 2.30.2117 nerves_system_br 1.34.4118 nerves_system_mangopi_mq_pro 0.17.2119 nerves_system_qemu_aarch64 0.4.2120 nerves_system_rpi0 2.1.2121 nerves_system_rpi4 2.1.2122 nerves_system_rpi5 2.1.2123 nerves_system_trellis 0.5.0124 nerves_system_x86_64 1.34.2125 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1126 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1127 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1128 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1129 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1130 nerves_uevent 0.1.7131 nimble_parsec 1.4.2132 openaimt 0.3.3133 parse_trans 3.4.1134 phoenix 1.7.24135 phoenix_ecto 4.7.0136 phoenix_html 3.3.4137 phoenix_live_view 0.18.18 VULNERABLE!138 EEF-CVE-2026-64941 (LOW)139 aka: CVE-2026-64941, GHSA-36m4-rm57-3prf140 Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR141 https://osv.dev/vulnerability/EEF-CVE-2026-64941142 phoenix_pubsub 2.3.0143 phoenix_template 1.1.0144 playwrightais 1.32.1-rc145 plug 1.20.3146 plug_cowboy 2.9.0147 plug_crypto 2.2.0148 postgrex 0.22.4149 property_table 0.3.4150 ranch 1.8.0151 readabilityais 0.11.1152 recase 0.9.1153 ring_buffer 0.1.0154 ring_logger 0.11.7155 solid 0.18.0156 ssl_verify_fun 1.1.7157 swoosh 1.28.1158 tablet 0.3.3159 tailwind 0.5.1160 telemetry 1.4.2161 telemetry_metrics 0.6.2162 telemetry_poller 1.3.0163 toolshed 0.5.0164 uboot_env 1.0.2165 unicode_util_compat 0.7.1166 uuid 1.1.8167 websock 0.5.3168 websock_adapter 0.5.9169Found packages with security advisories, see above for details170All dependencies have been fetched171==> ring_buffer172Compiling 1 file (.ex)173Generated ring_buffer app174==> dotx175warning: in order to compile .yrl files, you must add "compilers: [:yecc] ++ Mix.compilers()" to the "def project" section of dotx's mix.exs176Compiling 1 file (.yrl)177src/dot_parser.yrl: Warning: conflicts: 0 shift/reduce, 0 reduce/reduce178warning: in order to compile .xrl files, you must add "compilers: [:leex] ++ Mix.compilers()" to the "def project" section of dotx's mix.exs179Compiling 1 file (.xrl)180Compiling 2 files (.erl)181Compiling 4 files (.ex)182 warning: the variable "bytes" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator183 │184 102 │ <<prefix::binary-size(bytes)>> <> _ = html185 │ ~186 │187 └─ lib/dotx_decode.ex:102:37: Dotx.HTML.trim/1188189 warning: the variable "bytes" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator190 │191 107 │ Enum.map_join(lines, "\n", fn <<_::binary-size(bytes)>> <> rest -> rest; o -> o end)192 │ ~193 │194 └─ lib/dotx_decode.ex:107:66: Dotx.HTML.trim/1195196 warning: the right-hand side of || will always execute:197198 id199200 because the left-hand side always evaluates to:201202 dynamic(nil)203204 where "x" (context Kernel) was given the type:205206 # type: dynamic(nil)207 # from: lib/helpers.ex:32208 x209210 type warning found at:211 │212 32 │ {graph,i} = case id do nil-> {%{graph| id: id || "x#{i}"},i+1}; _-> {graph,i} end213 │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~214 │215 └─ lib/helpers.ex:32: Dotx.Helpers.identify/2216217Generated dotx app218==> nerves_compatibility_test219===> Analyzing applications...220===> Compiling cowlib221===> Compiling src/cow_sse.erl failed222 ┌─ src/cow_sse.erl:223 │224 56 │ -> {event, parsed_event(), State} | {more, State}.225 │ ╰── type variable 'State' is only used once (is unbound)226227228** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"