Build log
host
pleroma 0.9.0-develop.2dcded20 · fail · run pleroma-0.9.0-develop.2dcded20-1791070033763
178 of 178 lines
1Resolving Hex dependencies...2Resolution completed in 0.249s3Unchanged:4 cachex 3.6.05 calendar 0.16.16 certifi 2.15.07 circular_buffer 1.1.08 comeonin 4.1.29 connection 1.0.410 cowboy 1.1.2 VULNERABLE!11 GHSA-w4f7-4cxr-rv3c (MEDIUM)12 aka: CVE-2026-43966, EEF-CVE-2026-4396613 cowboy and gun affected by an HTTP Request/Response Splitting vulnerability14 https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c15 cowlib 1.0.2 VULNERABLE!16 EEF-CVE-2026-7790 (HIGH)17 aka: CVE-2026-7790, GHSA-32p9-57cr-4x6518 Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS19 https://osv.dev/vulnerability/EEF-CVE-2026-77902021 EEF-CVE-2026-43970 (HIGH)22 aka: CVE-2026-43970, GHSA-84f2-rp86-235p23 Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame24 https://osv.dev/vulnerability/EEF-CVE-2026-4397025 db_connection 1.1.326 decimal 1.9.0 VULNERABLE!27 EEF-CVE-2026-32686 (MEDIUM)28 aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v29 Unbounded exponent in decimal enables unauthenticated DoS30 https://osv.dev/vulnerability/EEF-CVE-2026-3268631 ecto 2.2.1232 elixir_make 0.10.033 eternal 1.2.234 expo 1.1.135 gettext 0.26.236 hackney 1.25.0 VULNERABLE!37 EEF-CVE-2026-47071 (HIGH)38 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr39 SOCKS5 TLS upgrade ignores caller timeout in hackney40 https://osv.dev/vulnerability/EEF-CVE-2026-470714142 EEF-CVE-2026-47076 (MEDIUM)43 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq44 SSRF allowlist bypass via percent-encoded host in hackney45 https://osv.dev/vulnerability/EEF-CVE-2026-470764647 EEF-CVE-2026-47069 (LOW)48 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw249 CRLF injection in cookie domain/path options in hackney50 https://osv.dev/vulnerability/EEF-CVE-2026-470695152 EEF-CVE-2026-47075 (MEDIUM)53 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf54 CR/LF injection in query parameter in hackney55 https://osv.dev/vulnerability/EEF-CVE-2026-4707556 html_sanitize_ex 1.3.0 VULNERABLE!57 EEF-CVE-2026-68749 (HIGH)58 aka: CVE-2026-68749, GHSA-4cx2-987x-rr2x59 Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service60 https://osv.dev/vulnerability/EEF-CVE-2026-687496162 EEF-CVE-2026-66370 (MEDIUM)63 aka: CVE-2026-66370, GHSA-w3f9-jjhw-wwvq64 html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking65 https://osv.dev/vulnerability/EEF-CVE-2026-663706667 EEF-CVE-2026-66829 (LOW)68 aka: CVE-2026-66829, GHSA-2c6f-3j54-xpcr69 html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection70 https://osv.dev/vulnerability/EEF-CVE-2026-668297172 EEF-CVE-2026-66843 (LOW)73 aka: CVE-2026-66843, GHSA-xmm9-jc22-rcgj74 html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding75 https://osv.dev/vulnerability/EEF-CVE-2026-668437677 EEF-CVE-2026-68747 (LOW)78 aka: CVE-2026-68747, GHSA-87v2-pfhj-r5x779 CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input80 https://osv.dev/vulnerability/EEF-CVE-2026-687478182 EEF-CVE-2026-68750 (HIGH)83 aka: CVE-2026-68750, GHSA-463q-p2fr-mh9p84 Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service85 https://osv.dev/vulnerability/EEF-CVE-2026-6875086 httpoison 1.1.187 idna 6.1.188 interactive_cmd 0.1.489 jason 1.4.590 jumper 1.0.291 metrics 1.0.192 mime 2.0.793 mimerl 1.5.094 mochiweb 2.22.095 nerves 2.0.0-pre.296 nerves_discovery 0.1.597 nerves_logging 0.2.498 nerves_runtime 0.13.1399 nerves_system_bbb 2.30.2100 nerves_system_br 1.34.4101 nerves_system_mangopi_mq_pro 0.17.2102 nerves_system_qemu_aarch64 0.4.2103 nerves_system_rpi0 2.1.2104 nerves_system_rpi4 2.1.2105 nerves_system_rpi5 2.1.2106 nerves_system_trellis 0.5.0107 nerves_system_x86_64 1.34.2108 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1109 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1110 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1111 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1112 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1113 nerves_uevent 0.1.7114 parse_trans 3.4.1115 pbkdf2_elixir 0.12.4116 phoenix 1.3.5 VULNERABLE!117 GHSA-p8f7-22gq-m7j9 (HIGH)118 aka: CVE-2022-42975119 Phoenix before 1.6.14 mishandles check_origin wildcarding120 https://osv.dev/vulnerability/GHSA-p8f7-22gq-m7j9121122 EEF-CVE-2026-56812 (MEDIUM)123 aka: CVE-2026-56812, GHSA-63mc-hw7g-86rr124 Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff125 https://osv.dev/vulnerability/EEF-CVE-2026-56812126127 EEF-CVE-2026-56811 (HIGH)128 aka: CVE-2026-56811, GHSA-6983-jfq8-485w129 Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service130 https://osv.dev/vulnerability/EEF-CVE-2026-56811131 phoenix_ecto 3.6.0132 phoenix_html 2.14.3 VULNERABLE!133 GHSA-5g2h-9x5v-5h3x (MEDIUM)134 aka: CVE-2021-46871, GHSA-j3gg-r6gp-95q2135 phoenix_html allows Cross-site Scripting in HEEx class attributes136 https://osv.dev/vulnerability/GHSA-5g2h-9x5v-5h3x137 phoenix_pubsub 1.1.2138 pleroma 0.9.0-develop.2dcded20 VULNERABLE!139 GHSA-2c28-m2m7-mf55 (LOW)140 aka: CVE-2023-5588141 Pleroma Path Traversal vulnerability142 https://osv.dev/vulnerability/GHSA-2c28-m2m7-mf55143 plug 1.20.3144 plug_crypto 2.2.0145 poison 3.1.0146 poolboy 1.5.2147 postgrex 0.13.5148 property_table 0.3.4149 ranch 1.3.2150 ring_logger 0.11.7151 sleeplocks 1.1.4152 ssl_verify_fun 1.1.7153 tablet 0.3.3154 telemetry 1.4.2155 toolshed 0.5.0156 trailing_format_plug 0.0.7157 tzdata 0.5.22158 uboot_env 1.0.2159 unicode_util_compat 0.7.1160 unsafe 1.0.2161Found packages with security advisories, see above for details162All dependencies have been fetched163 warning: String.strip/1 is deprecated. Use String.trim/1 instead164 │165 4 │ @version File.read!("VERSION") |> String.strip166 │ ~167 │168 └─ /work/proj/deps/poison/mix.exs:4:44: Poison.Mixfile (module)169170fatal: not a git repository (or any parent up to mount point /)171Stopping at filesystem boundary (GIT_DISCOVERY_ACROSS_FILESYSTEM not set).172Error while loading project :pleroma at /work/proj/deps/pleroma173** (ArgumentError) construction of binary failed: segment 2 of type 'binary': expected a binary but got: {"", 128}174 /work/proj/deps/pleroma/mix.exs:7: Pleroma.Mixfile.project/0175 (mix 1.20.3) lib/mix/project.ex:1093: Mix.Project.get_project_config/1176 (mix 1.20.3) lib/mix/project.ex:299: Mix.Project.push_config/2177 (mix 1.20.3) lib/mix/project.ex:262: Mix.Project.push/3178 (stdlib 8.1) lists.erl:2465: :lists.foldl/3