pleroma

Build log

nerves_system_qemu_aarch64

pleroma 0.9.0-develop.2dcded20 · fail · run pleroma-0.9.0-develop.2dcded20-1791070033763
247 of 247 lines
1Resolving Hex dependencies...2Resolution completed in 0.282s3Unchanged:4  cachex 3.6.05  calendar 0.16.16  certifi 2.15.07  circular_buffer 1.1.08  comeonin 4.1.29  connection 1.0.410  cowboy 1.1.2 VULNERABLE!11    GHSA-w4f7-4cxr-rv3c (MEDIUM)12    aka: CVE-2026-43966, EEF-CVE-2026-4396613    cowboy and gun affected by an HTTP Request/Response Splitting vulnerability14    https://osv.dev/vulnerability/GHSA-w4f7-4cxr-rv3c15  cowlib 1.0.2 VULNERABLE!16    EEF-CVE-2026-7790 (HIGH)17    aka: CVE-2026-7790, GHSA-32p9-57cr-4x6518    Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS19    https://osv.dev/vulnerability/EEF-CVE-2026-77902021    EEF-CVE-2026-43970 (HIGH)22    aka: CVE-2026-43970, GHSA-84f2-rp86-235p23    Decompression Bomb in cow_spdy:inflate/2 Allows Memory Exhaustion via Crafted SPDY Frame24    https://osv.dev/vulnerability/EEF-CVE-2026-4397025  db_connection 1.1.326  decimal 1.9.0 VULNERABLE!27    EEF-CVE-2026-32686 (MEDIUM)28    aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v29    Unbounded exponent in decimal enables unauthenticated DoS30    https://osv.dev/vulnerability/EEF-CVE-2026-3268631  ecto 2.2.1232  elixir_make 0.10.033  eternal 1.2.234  expo 1.1.135  gettext 0.26.236  hackney 1.25.0 VULNERABLE!37    EEF-CVE-2026-47071 (HIGH)38    aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr39    SOCKS5 TLS upgrade ignores caller timeout in hackney40    https://osv.dev/vulnerability/EEF-CVE-2026-470714142    EEF-CVE-2026-47076 (MEDIUM)43    aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq44    SSRF allowlist bypass via percent-encoded host in hackney45    https://osv.dev/vulnerability/EEF-CVE-2026-470764647    EEF-CVE-2026-47069 (LOW)48    aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw249    CRLF injection in cookie domain/path options in hackney50    https://osv.dev/vulnerability/EEF-CVE-2026-470695152    EEF-CVE-2026-47075 (MEDIUM)53    aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf54    CR/LF injection in query parameter in hackney55    https://osv.dev/vulnerability/EEF-CVE-2026-4707556  html_sanitize_ex 1.3.0 VULNERABLE!57    EEF-CVE-2026-68749 (HIGH)58    aka: CVE-2026-68749, GHSA-4cx2-987x-rr2x59    Quadratic regex backtracking in the html_sanitize_ex CSS scrubber allows CPU-exhaustion denial of service60    https://osv.dev/vulnerability/EEF-CVE-2026-687496162    EEF-CVE-2026-66370 (MEDIUM)63    aka: CVE-2026-66370, GHSA-w3f9-jjhw-wwvq64    html_sanitize_ex HTML5 scrubber keeps attacker-supplied form-association attributes, allowing form hijacking65    https://osv.dev/vulnerability/EEF-CVE-2026-663706667    EEF-CVE-2026-66829 (LOW)68    aka: CVE-2026-66829, GHSA-2c6f-3j54-xpcr69    html_sanitize_ex HTML5 scrubber keeps attacker-supplied meta refresh, allowing forced cross-origin redirection70    https://osv.dev/vulnerability/EEF-CVE-2026-668297172    EEF-CVE-2026-66843 (LOW)73    aka: CVE-2026-66843, GHSA-xmm9-jc22-rcgj74    html_sanitize_ex HTML5 scrubber keeps attacker-supplied `<object>` elements, allowing untrusted content embedding75    https://osv.dev/vulnerability/EEF-CVE-2026-668437677    EEF-CVE-2026-68747 (LOW)78    aka: CVE-2026-68747, GHSA-87v2-pfhj-r5x779    CSS sanitizer allowlist bypass in html_sanitize_ex via non-declaration input80    https://osv.dev/vulnerability/EEF-CVE-2026-687478182    EEF-CVE-2026-68750 (HIGH)83    aka: CVE-2026-68750, GHSA-463q-p2fr-mh9p84    Quadratic sibling re-flattening in the html_sanitize_ex traversal engine allows CPU-exhaustion denial of service85    https://osv.dev/vulnerability/EEF-CVE-2026-6875086  httpoison 1.1.187  idna 6.1.188  interactive_cmd 0.1.489  jason 1.4.590  jumper 1.0.291  metrics 1.0.192  mime 2.0.793  mimerl 1.5.094  mochiweb 2.22.095  nerves 2.0.0-pre.296  nerves_discovery 0.1.597  nerves_logging 0.2.498  nerves_runtime 0.13.1399  nerves_system_bbb 2.30.2100  nerves_system_br 1.34.4101  nerves_system_mangopi_mq_pro 0.17.2102  nerves_system_qemu_aarch64 0.4.2103  nerves_system_rpi0 2.1.2104  nerves_system_rpi4 2.1.2105  nerves_system_rpi5 2.1.2106  nerves_system_trellis 0.5.0107  nerves_system_x86_64 1.34.2108  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.1109  nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.1110  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.1111  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.1112  nerves_toolchain_x86_64_nerves_linux_musl 15.3.1113  nerves_uevent 0.1.7114  parse_trans 3.4.1115  pbkdf2_elixir 0.12.4116  phoenix 1.3.5 VULNERABLE!117    GHSA-p8f7-22gq-m7j9 (HIGH)118    aka: CVE-2022-42975119    Phoenix before 1.6.14 mishandles check_origin wildcarding120    https://osv.dev/vulnerability/GHSA-p8f7-22gq-m7j9121122    EEF-CVE-2026-56812 (MEDIUM)123    aka: CVE-2026-56812, GHSA-63mc-hw7g-86rr124    Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff125    https://osv.dev/vulnerability/EEF-CVE-2026-56812126127    EEF-CVE-2026-56811 (HIGH)128    aka: CVE-2026-56811, GHSA-6983-jfq8-485w129    Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service130    https://osv.dev/vulnerability/EEF-CVE-2026-56811131  phoenix_ecto 3.6.0132  phoenix_html 2.14.3 VULNERABLE!133    GHSA-5g2h-9x5v-5h3x (MEDIUM)134    aka: CVE-2021-46871, GHSA-j3gg-r6gp-95q2135    phoenix_html allows Cross-site Scripting in HEEx class attributes136    https://osv.dev/vulnerability/GHSA-5g2h-9x5v-5h3x137  phoenix_pubsub 1.1.2138  pleroma 0.9.0-develop.2dcded20 VULNERABLE!139    GHSA-2c28-m2m7-mf55 (LOW)140    aka: CVE-2023-5588141    Pleroma Path Traversal vulnerability142    https://osv.dev/vulnerability/GHSA-2c28-m2m7-mf55143  plug 1.20.3144  plug_crypto 2.2.0145  poison 3.1.0146  poolboy 1.5.2147  postgrex 0.13.5148  property_table 0.3.4149  ranch 1.3.2150  ring_logger 0.11.7151  sleeplocks 1.1.4152  ssl_verify_fun 1.1.7153  tablet 0.3.3154  telemetry 1.4.2155  toolshed 0.5.0156  trailing_format_plug 0.0.7157  tzdata 0.5.22158  uboot_env 1.0.2159  unicode_util_compat 0.7.1160  unsafe 1.0.2161* Getting pleroma (Hex package)162* Getting nerves (Hex package)163* Getting ring_logger (Hex package)164* Getting toolshed (Hex package)165* Getting nerves_runtime (Hex package)166* Getting nerves_system_bbb (Hex package)167* Getting nerves_system_mangopi_mq_pro (Hex package)168* Getting nerves_system_qemu_aarch64 (Hex package)169* Getting nerves_system_rpi0 (Hex package)170* Getting nerves_system_rpi4 (Hex package)171* Getting nerves_system_rpi5 (Hex package)172* Getting nerves_system_trellis (Hex package)173* Getting nerves_system_x86_64 (Hex package)174* Getting nerves_system_br (Hex package)175* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)176* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)177* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)178* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)179* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)180* Getting nerves_logging (Hex package)181* Getting nerves_uevent (Hex package)182* Getting uboot_env (Hex package)183* Getting elixir_make (Hex package)184* Getting property_table (Hex package)185* Getting circular_buffer (Hex package)186* Getting interactive_cmd (Hex package)187* Getting nerves_discovery (Hex package)188* Getting tablet (Hex package)189* Getting cachex (Hex package)190* Getting calendar (Hex package)191* Getting comeonin (Hex package)192* Getting cowboy (Hex package)193* Getting gettext (Hex package)194* Getting html_sanitize_ex (Hex package)195* Getting httpoison (Hex package)196* Getting jason (Hex package)197* Getting pbkdf2_elixir (Hex package)198* Getting phoenix (Hex package)199* Getting phoenix_ecto (Hex package)200* Getting phoenix_html (Hex package)201* Getting phoenix_pubsub (Hex package)202* Getting postgrex (Hex package)203* Getting trailing_format_plug (Hex package)204* Getting plug (Hex package)205* Getting mime (Hex package)206* Getting plug_crypto (Hex package)207* Getting telemetry (Hex package)208* Getting connection (Hex package)209* Getting db_connection (Hex package)210* Getting decimal (Hex package)211* Getting ecto (Hex package)212* Getting poolboy (Hex package)213* Getting poison (Hex package)214* Getting hackney (Hex package)215* Getting certifi (Hex package)216* Getting idna (Hex package)217* Getting metrics (Hex package)218* Getting mimerl (Hex package)219* Getting parse_trans (Hex package)220* Getting ssl_verify_fun (Hex package)221* Getting unicode_util_compat (Hex package)222* Getting mochiweb (Hex package)223* Getting expo (Hex package)224* Getting cowlib (Hex package)225* Getting ranch (Hex package)226* Getting tzdata (Hex package)227* Getting eternal (Hex package)228* Getting jumper (Hex package)229* Getting sleeplocks (Hex package)230* Getting unsafe (Hex package)231Found packages with security advisories, see above for details232    warning: String.strip/1 is deprecated. Use String.trim/1 instead233    │234  4 │   @version File.read!("VERSION") |> String.strip235    │                                            ~236    │237    └─ /work/proj/deps_qemu_aarch64/poison/mix.exs:4:44: Poison.Mixfile (module)238239fatal: not a git repository (or any parent up to mount point /)240Stopping at filesystem boundary (GIT_DISCOVERY_ACROSS_FILESYSTEM not set).241Error while loading project :pleroma at /work/proj/deps_qemu_aarch64/pleroma242** (ArgumentError) construction of binary failed: segment 2 of type 'binary': expected a binary but got: {"", 128}243    /work/proj/deps_qemu_aarch64/pleroma/mix.exs:7: Pleroma.Mixfile.project/0244    (mix 1.20.3) lib/mix/project.ex:1093: Mix.Project.get_project_config/1245    (mix 1.20.3) lib/mix/project.ex:299: Mix.Project.push_config/2246    (mix 1.20.3) lib/mix/project.ex:262: Mix.Project.push/3247    (stdlib 8.1) lists.erl:2465: :lists.foldl/3