helix

Build log

host

helix 0.1.6-rc · fail · run helix-0.1.6-rc-1791193982326
228 of 228 lines
1Resolving Hex dependencies...2Resolution completed in 0.832s3Unchanged:4  castore 1.0.215  certifi 2.15.06  circular_buffer 1.1.07  colour_hash 1.0.38  cowboy 2.9.0 VULNERABLE!9    EEF-CVE-2026-8466 (HIGH)10    aka: CVE-2026-8466, GHSA-jfc2-q6qh-g5x811    Unbounded buffer accumulation in multipart header parsing causes denial of service in cowboy12    https://osv.dev/vulnerability/EEF-CVE-2026-84661314    GHSA-w4f7-4cxr-rv3c (MEDIUM)15    aka: CVE-2026-43966, EEF-CVE-2026-4396616    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability17    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c1819    EEF-CVE-2026-65624 (MEDIUM)20    aka: CVE-2026-6562421    Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion22    https://osv.dev/vulnerability/EEF-CVE-2026-6562423  cowboy_telemetry 0.4.024  cowlib 2.11.0 VULNERABLE!25    EEF-CVE-2026-7790 (HIGH)26    aka: CVE-2026-7790, GHSA-32p9-57cr-4x6527    Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS28    https://osv.dev/vulnerability/EEF-CVE-2026-77902930    EEF-CVE-2026-43968 (MEDIUM)31    aka: CVE-2026-43968, GHSA-hv23-4qp7-8c8r32    CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/133    https://osv.dev/vulnerability/EEF-CVE-2026-439683435    EEF-CVE-2026-43970 (HIGH)36    aka: CVE-2026-43970, GHSA-84f2-rp86-235p37    Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame38    https://osv.dev/vulnerability/EEF-CVE-2026-439703940    EEF-CVE-2026-59248 (HIGH)41    aka: CVE-2026-5924842    Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS43    https://osv.dev/vulnerability/EEF-CVE-2026-592484445    EEF-CVE-2026-43969 (LOW)46    aka: CVE-2026-43969, GHSA-g2wm-735q-3f5647    Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/148    https://osv.dev/vulnerability/EEF-CVE-2026-439694950    EEF-CVE-2026-43966 (MEDIUM)51    aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c52    HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/253    https://osv.dev/vulnerability/EEF-CVE-2026-439665455    EEF-CVE-2026-43971 (MEDIUM)56    aka: CVE-2026-4397157    Link Header Directive Smuggling via Unescaped target/rel/Attribute Keys in cow_link:link/158    https://osv.dev/vulnerability/EEF-CVE-2026-4397159  db_connection 2.10.260  decimal 3.1.161  dotx 0.3.162  ecto 3.14.263  ecto_sql 3.14.064  elixir_make 0.10.065  esbuild 0.10.066  expo 1.1.167  file_system 1.1.168  floki 0.38.469  gettext 0.26.270  gun 2.0.0-rc.2 VULNERABLE!71    EEF-CVE-2026-43973 (HIGH)72    aka: CVE-2026-43973, GHSA-r53j-fjj5-mv7773    gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion74    https://osv.dev/vulnerability/EEF-CVE-2026-439737576    GHSA-w4f7-4cxr-rv3c (MEDIUM)77    aka: CVE-2026-43966, EEF-CVE-2026-4396678    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability79    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c80  hackney 1.25.0 VULNERABLE!81    EEF-CVE-2026-47071 (HIGH)82    aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr83    SOCKS5 TLS upgrade ignores caller timeout in hackney84    https://osv.dev/vulnerability/EEF-CVE-2026-470718586    EEF-CVE-2026-47076 (MEDIUM)87    aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq88    SSRF allowlist bypass via percent-encoded host in hackney89    https://osv.dev/vulnerability/EEF-CVE-2026-470769091    EEF-CVE-2026-47069 (LOW)92    aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw293    CRLF injection in cookie domain/path options in hackney94    https://osv.dev/vulnerability/EEF-CVE-2026-470699596    EEF-CVE-2026-47075 (MEDIUM)97    aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf98    CR/LF injection in query parameter in hackney99    https://osv.dev/vulnerability/EEF-CVE-2026-47075100  helix 0.1.6-rc101  httpoison 1.8.2102  idna 6.1.1103  interactive_cmd 0.1.4104  jason 1.4.5105  json 1.4.1106  meck 0.9.2107  metrics 1.0.1108  mime 2.0.7109  mimerl 1.5.0110  mix_test_watch 1.4.0111  mock 0.3.9112  nerves 2.0.0-pre.2113  nerves_discovery 0.1.5114  nerves_logging 0.2.4115  nerves_runtime 0.13.13116  nerves_system_bbb 2.30.2117  nerves_system_br 1.34.4118  nerves_system_mangopi_mq_pro 0.17.2119  nerves_system_qemu_aarch64 0.4.2120  nerves_system_rpi0 2.1.2121  nerves_system_rpi4 2.1.2122  nerves_system_rpi5 2.1.2123  nerves_system_trellis 0.5.0124  nerves_system_x86_64 1.34.2125  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1126  nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1127  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1128  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1129  nerves_toolchain_x86_64_nerves_linux_musl 15.3.1130  nerves_uevent 0.1.7131  nimble_parsec 1.4.2132  openaimt 0.3.3133  parse_trans 3.4.1134  phoenix 1.7.24135  phoenix_ecto 4.7.0136  phoenix_html 3.3.4137  phoenix_live_view 0.18.18 VULNERABLE!138    EEF-CVE-2026-64941 (LOW)139    aka: CVE-2026-64941, GHSA-36m4-rm57-3prf140    Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR141    https://osv.dev/vulnerability/EEF-CVE-2026-64941142  phoenix_pubsub 2.3.0143  phoenix_template 1.1.0144  playwrightais 1.32.1-rc145  plug 1.20.3146  plug_cowboy 2.9.0147  plug_crypto 2.2.0148  postgrex 0.22.4149  property_table 0.3.4150  ranch 1.8.0151  readabilityais 0.11.1152  recase 0.9.1153  ring_buffer 0.1.0154  ring_logger 0.11.7155  solid 0.18.0156  ssl_verify_fun 1.1.7157  swoosh 1.28.1158  tablet 0.3.3159  tailwind 0.5.1160  telemetry 1.4.2161  telemetry_metrics 0.6.2162  telemetry_poller 1.3.0163  toolshed 0.5.0164  uboot_env 1.0.2165  unicode_util_compat 0.7.1166  uuid 1.1.8167  websock 0.5.3168  websock_adapter 0.5.9169Found packages with security advisories, see above for details170All dependencies have been fetched171==> ring_buffer172Compiling 1 file (.ex)173Generated ring_buffer app174==> dotx175warning: in order to compile .yrl files, you must add "compilers: [:yecc] ++ Mix.compilers()" to the "def project" section of dotx's mix.exs176Compiling 1 file (.yrl)177src/dot_parser.yrl: Warning: conflicts: 0 shift/reduce, 0 reduce/reduce178warning: in order to compile .xrl files, you must add "compilers: [:leex] ++ Mix.compilers()" to the "def project" section of dotx's mix.exs179Compiling 1 file (.xrl)180Compiling 2 files (.erl)181Compiling 4 files (.ex)182     warning: the variable "bytes" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator183     │184 102 │               <<prefix::binary-size(bytes)>> <> _ = html185     │                                     ~186     │187     └─ lib/dotx_decode.ex:102:37: Dotx.HTML.trim/1188189     warning: the variable "bytes" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator190     │191 107 │                   Enum.map_join(lines, "\n", fn <<_::binary-size(bytes)>> <> rest -> rest; o -> o end)192     │                                                                  ~193     │194     └─ lib/dotx_decode.ex:107:66: Dotx.HTML.trim/1195196    warning: the right-hand side of || will always execute:197198        id199200    because the left-hand side always evaluates to:201202        dynamic(nil)203204    where "x" (context Kernel) was given the type:205206        # type: dynamic(nil)207        # from: lib/helpers.ex:32208        x209210    type warning found at:211    │212 32 │     {graph,i} = case id do nil-> {%{graph| id: id || "x#{i}"},i+1}; _-> {graph,i} end213    │     ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~214    │215    └─ lib/helpers.ex:32: Dotx.Helpers.identify/2216217Generated dotx app218==> nerves_compatibility_test219===> Analyzing applications...220===> Compiling cowlib221===> Compiling src/cow_sse.erl failed222    ┌─ src/cow_sse.erl:223    │224 56 │  	-> {event, parsed_event(), State} | {more, State}.225    │  	                           ╰── type variable 'State' is only used once (is unbound)226227228** (Mix) Could not compile dependency :cowlib, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile cowlib --force", update it with "mix deps.update cowlib" or clean it with "mix deps.clean cowlib"