Build log
host
plug_mishka_auth 0.0.2 · fail · run plug_mishka_auth-0.0.2-1791070543086
559 of 559 lines
1Resolving Hex dependencies...2Resolution completed in 0.423s3Unchanged:4 bamboo 1.7.15 bamboo_smtp 3.1.36 bcrypt_elixir 2.3.17 certifi 2.15.08 circular_buffer 1.1.09 combine 0.10.010 comeonin 5.5.111 db_connection 2.10.212 decimal 2.4.1 VULNERABLE!13 EEF-CVE-2026-32686 (MEDIUM)14 aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v15 Unbounded exponent in decimal enables unauthenticated DoS16 https://osv.dev/vulnerability/EEF-CVE-2026-3268617 ecto 3.11.218 ecto_enum 1.4.019 ecto_sql 3.11.320 elixir_make 0.10.021 expo 1.1.122 gen_smtp 1.1.123 gettext 0.26.224 guardian 2.5.025 hackney 1.25.0 VULNERABLE!26 EEF-CVE-2026-47071 (HIGH)27 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr28 SOCKS5 TLS upgrade ignores caller timeout in hackney29 https://osv.dev/vulnerability/EEF-CVE-2026-470713031 EEF-CVE-2026-47076 (MEDIUM)32 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq33 SSRF allowlist bypass via percent-encoded host in hackney34 https://osv.dev/vulnerability/EEF-CVE-2026-470763536 EEF-CVE-2026-47069 (LOW)37 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw238 CRLF injection in cookie domain/path options in hackney39 https://osv.dev/vulnerability/EEF-CVE-2026-470694041 EEF-CVE-2026-47075 (MEDIUM)42 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf43 CR/LF injection in query parameter in hackney44 https://osv.dev/vulnerability/EEF-CVE-2026-4707545 httpoison 1.8.246 hut 1.3.047 idna 6.1.148 interactive_cmd 0.1.449 jose 1.11.1250 metrics 1.0.151 mime 1.6.052 mimerl 1.5.053 nerves 2.0.0-pre.254 nerves_discovery 0.1.555 nerves_logging 0.2.456 nerves_runtime 0.13.1357 nerves_system_bbb 2.30.258 nerves_system_br 1.34.459 nerves_system_mangopi_mq_pro 0.17.260 nerves_system_qemu_aarch64 0.4.261 nerves_system_rpi0 2.1.262 nerves_system_rpi4 2.1.263 nerves_system_rpi5 2.1.264 nerves_system_trellis 0.5.065 nerves_system_x86_64 1.34.266 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.167 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.168 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.169 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.170 nerves_toolchain_x86_64_nerves_linux_musl 15.3.171 nerves_uevent 0.1.772 oauth2 2.1.173 parse_trans 3.4.174 phoenix 1.8.1575 phoenix_pubsub 2.3.076 phoenix_template 1.1.077 plug 1.20.378 plug_crypto 2.2.079 plug_mishka_auth 0.0.280 poison 4.0.181 property_table 0.3.482 ranch 2.3.083 redix 0.11.284 ring_logger 0.11.785 scrivener 2.7.286 scrivener_ecto 2.7.187 ssl_verify_fun 1.1.788 tablet 0.3.389 telemetry 0.4.390 tesla 1.21.391 timex 3.7.1392 toolshed 0.5.093 tzdata 1.2.294 uboot_env 1.0.295 ueberauth 0.6.396 ueberauth_github 0.8.097 ueberauth_google 0.9.098 unicode_util_compat 0.7.199 websock 0.5.3100 websock_adapter 0.6.0101Found packages with security advisories, see above for details102All dependencies have been fetched103==> poison104Compiling 4 files (.ex)105 warning: using single-quoted strings to represent charlists is deprecated.106 Use ~c"" if you indeed want a charlist or use "" instead.107 You may run "mix format --migrate" to change all single-quoted108 strings to use the ~c sigil and fix this warning.109 │110 127 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do111 │ ~112 │113 └─ lib/poison/encoder.ex:127:31114115 warning: using single-quoted strings to represent charlists is deprecated.116 Use ~c"" if you indeed want a charlist or use "" instead.117 You may run "mix format --migrate" to change all single-quoted118 strings to use the ~c sigil and fix this warning.119 │120 127 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do121 │ ~122 │123 └─ lib/poison/encoder.ex:127:48124125 warning: using single-quoted strings to represent charlists is deprecated.126 Use ~c"" if you indeed want a charlist or use "" instead.127 You may run "mix format --migrate" to change all single-quoted128 strings to use the ~c sigil and fix this warning.129 │130 174 │ when char <= 0x1F or char in '"\\' do131 │ ~132 │133 └─ lib/poison/encoder.ex:174:37134135 warning: using single-quoted strings to represent charlists is deprecated.136 Use ~c"" if you indeed want a charlist or use "" instead.137 You may run "mix format --migrate" to change all single-quoted138 strings to use the ~c sigil and fix this warning.139 │140 94 │ when char in '-0123456789' do141 │ ~142 │143 └─ lib/poison/parser.ex:94:21144145 warning: using single-quoted strings to represent charlists is deprecated.146 Use ~c"" if you indeed want a charlist or use "" instead.147 You may run "mix format --migrate" to change all single-quoted148 strings to use the ~c sigil and fix this warning.149 │150 189 │ when char in '123456789' do151 │ ~152 │153 └─ lib/poison/parser.ex:189:21154155 warning: using single-quoted strings to represent charlists is deprecated.156 Use ~c"" if you indeed want a charlist or use "" instead.157 You may run "mix format --migrate" to change all single-quoted158 strings to use the ~c sigil and fix this warning.159 │160 205 │ defp number_exp(<<e>> <> rest, frac, pos, acc) when e in 'eE' do161 │ ~162 │163 └─ lib/poison/parser.ex:205:60164165 warning: using single-quoted strings to represent charlists is deprecated.166 Use ~c"" if you indeed want a charlist or use "" instead.167 You may run "mix format --migrate" to change all single-quoted168 strings to use the ~c sigil and fix this warning.169 │170 238 │ when char in '0123456789' do171 │ ~172 │173 └─ lib/poison/parser.ex:238:21174175 warning: using single-quoted strings to represent charlists is deprecated.176 Use ~c"" if you indeed want a charlist or use "" instead.177 You may run "mix format --migrate" to change all single-quoted178 strings to use the ~c sigil and fix this warning.179 │180 246 │ defp number_digits_count(<<char>> <> rest, acc) when char in '0123456789' do181 │ ~182 │183 └─ lib/poison/parser.ex:246:64184185 warning: using single-quoted strings to represent charlists is deprecated.186 Use ~c"" if you indeed want a charlist or use "" instead.187 You may run "mix format --migrate" to change all single-quoted188 strings to use the ~c sigil and fix this warning.189 │190 270 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do191 │ ~192 │193 └─ lib/poison/parser.ex:270:31194195 warning: using single-quoted strings to represent charlists is deprecated.196 Use ~c"" if you indeed want a charlist or use "" instead.197 You may run "mix format --migrate" to change all single-quoted198 strings to use the ~c sigil and fix this warning.199 │200 270 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do201 │ ~202 │203 └─ lib/poison/parser.ex:270:44204205 warning: using single-quoted strings to represent charlists is deprecated.206 Use ~c"" if you indeed want a charlist or use "" instead.207 You may run "mix format --migrate" to change all single-quoted208 strings to use the ~c sigil and fix this warning.209 │210 277 │ when a1 in 'dD' and a2 in 'dD' and b1 in '89abAB' and211 │ ~212 │213 └─ lib/poison/parser.ex:277:24214215 warning: using single-quoted strings to represent charlists is deprecated.216 Use ~c"" if you indeed want a charlist or use "" instead.217 You may run "mix format --migrate" to change all single-quoted218 strings to use the ~c sigil and fix this warning.219 │220 277 │ when a1 in 'dD' and a2 in 'dD' and b1 in '89abAB' and221 │ ~222 │223 └─ lib/poison/parser.ex:277:39224225 warning: using single-quoted strings to represent charlists is deprecated.226 Use ~c"" if you indeed want a charlist or use "" instead.227 You may run "mix format --migrate" to change all single-quoted228 strings to use the ~c sigil and fix this warning.229 │230 277 │ when a1 in 'dD' and a2 in 'dD' and b1 in '89abAB' and231 │ ~232 │233 └─ lib/poison/parser.ex:277:54234235 warning: using single-quoted strings to represent charlists is deprecated.236 Use ~c"" if you indeed want a charlist or use "" instead.237 You may run "mix format --migrate" to change all single-quoted238 strings to use the ~c sigil and fix this warning.239 │240 334 │ defp skip_whitespace(<<char>> <> rest, pos) when char in '\s\n\t\r' do241 │ ~242 │243 └─ lib/poison/parser.ex:334:60244245 warning: Application.get_env/2 is discouraged in the module body, use Application.compile_env/3 instead246 │247 42 │ if Application.get_env(:poison, :native) do248 │ ~249 │250 └─ lib/poison/parser.ex:42:18: Poison.Parser (module)251252 warning: use Bitwise is deprecated. import Bitwise instead253 │254 46 │ use Bitwise255 │ ~~~~~~~~~~~256 │257 └─ lib/poison/parser.ex:46: Poison.Parser (module)258259 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator260 │261 240 │ <<digits::binary-size(count), rest::binary>> = string262 │ ~263 │264 └─ lib/poison/parser.ex:240:27: Poison.Parser.number_digits/2265266 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator267 │268 266 │ <<chunk::binary-size(count), rest::binary>> = string269 │ ~270 │271 └─ lib/poison/parser.ex:266:26: Poison.Parser.string_continue/3272273 warning: use Bitwise is deprecated. import Bitwise instead274 │275 117 │ use Bitwise276 │ ~~~~~~~~~~~277 │278 └─ lib/poison/encoder.ex:117: Poison.Encoder.BitString (module)279280 warning: the variable "size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator281 │282 169 │ <<chunk::binary-size(size), rest::binary>> = string283 │ ~284 │285 └─ lib/poison/encoder.ex:169:26: Poison.Encoder.BitString.escape/2286287Generated poison app288==> bcrypt_elixir289mkdir -p /work/proj/_build/host/lib/bcrypt_elixir/priv290cc -g -O3 -Wall -Wno-format-truncation -I"/usr/local/lib/erlang/erts-17.1/include" -Ic_src -fPIC -shared c_src/bcrypt_nif.c c_src/blowfish.c -o /work/proj/_build/host/lib/bcrypt_elixir/priv/bcrypt_nif.so291Compiling 3 files (.ex)292 warning: using single-quoted strings to represent charlists is deprecated.293 Use ~c"" if you indeed want a charlist or use "" instead.294 You may run "mix format --migrate" to change all single-quoted295 strings to use the ~c sigil and fix this warning.296 │297 57 │ path = :filename.join(:code.priv_dir(:bcrypt_elixir), 'bcrypt_nif')298 │ ~299 │300 └─ lib/bcrypt/base.ex:57:59301302 warning: use Bitwise is deprecated. import Bitwise instead303 │304 6 │ use Bitwise305 │ ~~~~~~~~~~~306 │307 └─ lib/bcrypt/base.ex:6: Bcrypt.Base (module)308309Generated bcrypt_elixir app310==> redix311Compiling 11 files (.ex)312 warning: using single-quoted strings to represent charlists is deprecated.313 Use ~c"" if you indeed want a charlist or use "" instead.314 You may run "mix format --migrate" to change all single-quoted315 strings to use the ~c sigil and fix this warning.316 │317 64 │ 'unknown POSIX error' -> inspect(reason)318 │ ~319 │320 └─ lib/redix/exceptions.ex:64:7321322 warning: the variable "size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator323 │324 176 │ <<str::bytes-size(size), @crlf, rest::binary>> ->325 │ ~326 │327 └─ lib/redix/protocol.ex:176:25: Redix.Protocol.parse_string_of_known_size/2328329 warning: a struct for Redix.PubSub.Connection is expected on struct update:330331 %Redix.PubSub.Connection{332 data333 | socket: socket,334 last_disconnect_reason: nil,335 backoff_current: nil,336 connected_address: address337 }338339 but got type:340341 dynamic(%{342 ...,343 last_disconnect_reason: term(),344 opts: empty_list() or non_empty_list(term(), term()),345 transport: :gen_tcp or :ssl346 })347348 where "data" was given the types:349350 # type: dynamic(%{..., opts: empty_list() or non_empty_list(term(), term())})351 # from: lib/redix/pubsub/connection.ex:107:46352 Redix.Connector.connect(data.opts, _conn_pid = self())353354 # type: dynamic(%{..., opts: empty_list() or non_empty_list(term(), term()), transport: :gen_tcp or :ssl})355 # from: lib/redix/pubsub/connection.ex:108:17356 setopts(data, socket, active: :once)357358 # type: dynamic(%{359 ...,360 last_disconnect_reason: term(),361 opts: empty_list() or non_empty_list(term(), term()),362 transport: :gen_tcp or :ssl363 })364 # from: lib/redix/pubsub/connection.ex:113365 data.last_disconnect_reason == nil366367 when defining the variable "data", you must also pattern match on "%Redix.PubSub.Connection{}"368369 type warning found at:370 │371 116 │ data = %__MODULE__{372 │ ~373 │374 └─ lib/redix/pubsub/connection.ex:116:14: Redix.PubSub.Connection.disconnected/3375376 warning: CAStore.file_path/0 is undefined (module CAStore is not available or is yet to be defined). Make sure the module name is correct and has been specified in full (or that an alias has been defined)377 │378 200 │ [{:cacertfile, ca_store_mod.file_path()} | @default_ssl_opts]379 │ ~380 │381 └─ lib/redix/connector.ex:200:37: Redix.Connector.build_socket_opts/2382383Generated redix app384==> ecto385Compiling 56 files (.ex)386 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead387 │388 297 │ @spec insert(389 │ ~~~~~~~~~~~~~390 │391 └─ lib/ecto/multi.ex:297: Ecto.Multi (module)392393 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead394 │395 338 │ @spec update(t, name, Changeset.t() | fun(Changeset.t()), Keyword.t()) :: t396 │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~397 │398 └─ lib/ecto/multi.ex:338: Ecto.Multi (module)399400 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead401 │402 371 │ @spec insert_or_update(t, name, Changeset.t() | fun(Changeset.t()), Keyword.t()) :: t403 │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~404 │405 └─ lib/ecto/multi.ex:371: Ecto.Multi (module)406407 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead408 │409 417 │ @spec delete(410 │ ~~~~~~~~~~~~~411 │412 └─ lib/ecto/multi.ex:417: Ecto.Multi (module)413414 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead415 │416 451 │ @spec one(417 │ ~~~~~~~~~~418 │419 └─ lib/ecto/multi.ex:451: Ecto.Multi (module)420421 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead422 │423 482 │ @spec all(424 │ ~~~~~~~~~~425 │426 └─ lib/ecto/multi.ex:482: Ecto.Multi (module)427428 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead429 │430 513 │ @spec exists?(431 │ ~~~~~~~~~~~~~~432 │433 └─ lib/ecto/multi.ex:513: Ecto.Multi (module)434435 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead436 │437 623 │ @spec insert_all(438 │ ~~~~~~~~~~~~~~~~~439 │440 └─ lib/ecto/multi.ex:623: Ecto.Multi (module)441442 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead443 │444 667 │ @spec update_all(445 │ ~~~~~~~~~~~~~~~~~446 │447 └─ lib/ecto/multi.ex:667: Ecto.Multi (module)448449 warning: fun/1 is not valid in typespecs. Either specify fun() or use (... -> return) instead450 │451 712 │ @spec delete_all(t, name, Ecto.Queryable.t() | fun(Ecto.Queryable.t()), Keyword.t()) :: t452 │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~453 │454 └─ lib/ecto/multi.ex:712: Ecto.Multi (module)455456 warning: BadStructError.exception/1 is undefined (module BadStructError is not available or is yet to be defined). Make sure the module name is correct and has been specified in full (or that an alias has been defined)457 │458 347 │ raise BadStructError, struct: struct, term: data459 │ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~460 │461 └─ lib/ecto/repo/queryable.ex:347: Ecto.Repo.Queryable.process/4462463Generated ecto app464==> db_connection465Compiling 18 files (.ex)466Generated db_connection app467warning: "xref: [exclude: ...]" in your mix.exs file is deprecated, instead use: "elixirc_options: [no_warn_undefined: ...]"468 (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:243: Mix.Tasks.Compile.Elixir.xref_exclude_opts/2469 (mix 1.20.3) lib/mix/tasks/compile.elixir.ex:142: Mix.Tasks.Compile.Elixir.run/1470 (mix 1.20.3) lib/mix/task.ex:502: anonymous fn/3 in Mix.Task.run_task/5471 (mix 1.20.3) lib/mix/task.compiler.ex:299: Mix.Task.Compiler.run_compiler/2472 (mix 1.20.3) lib/mix/task.compiler.ex:287: Mix.Task.Compiler.run/4473 (mix 1.20.3) lib/mix/tasks/compile.all.ex:75: Mix.Tasks.Compile.All.do_run/2474475==> ecto_sql476Compiling 25 files (.ex)477 warning: unused require Ecto.Query478 │479 140 │ require Ecto.Query480 │ ~481 │482 └─ lib/ecto/adapters/tds.ex:140:3483484 warning: unused require Logger485 │486 139 │ require Logger487 │ ~488 │489 └─ lib/ecto/adapters/tds.ex:139:3490491 warning: unused require Ecto.Query492 │493 107 │ require Ecto.Query494 │ ~495 │496 └─ lib/ecto/migrator.ex:107:3497498 warning: this clause of defp validate_index_opts!/1 is never used (or it will always fail/warn when invoked)499 │500 1558 │ defp validate_index_opts!(opts), do: opts501 │ ~502 │503 └─ lib/ecto/migration.ex:1558:8: Ecto.Migration.validate_index_opts!/1504505 warning: List.zip/1 is deprecated. Use Enum.zip/1 instead506 │507 681 │ |> List.zip()508 │ ~509 │510 └─ lib/ecto/adapters/sql.ex:681:15: Ecto.Adapters.SQL.format_table/1511 └─ lib/ecto/adapters/sql.ex:712:15: Ecto.Adapters.SQL.cells/2512513Generated ecto_sql app514==> ecto_enum515Compiling 5 files (.ex)516Generated ecto_enum app517==> scrivener_ecto518Compiling 2 files (.ex)519Generated scrivener_ecto app520==> guardian521Compiling 25 files (.ex)522Generated guardian app523==> ueberauth524Compiling 9 files (.ex)525Generated ueberauth app526==> nerves_compatibility_test527===> Analyzing applications...528===> Compiling hut529===> Analyzing applications...530===> Compiling gen_smtp531 ┌─ src/gen_smtp_server_session.erl:532 │533 323 │ case catch Module:code_change(OldVsn, CallbackState, Extra) of534 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.535Compile directive 'nowarn_deprecated_catch' can be used to suppress536warnings in selected modules.537538 ┌─ src/gen_smtp_server_session.erl:539 │540 464 │ crypto:start(), % ensure crypto is started, we're gonna need it541 │ ╰── Warning: crypto:start/0 is deprecated; use application:start(crypto) instead542543544 ┌─ src/gen_smtp_client.erl:545 │546 661 │ case catch smtp_socket:to_ssl_client(Socket, [binary | proplists:get_value(tls_options, Options, [])], 5000) of547 │ ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.548Compile directive 'nowarn_deprecated_catch' can be used to suppress549warnings in selected modules.550551552===> Compiling src/smtp_server_example.erl failed553 ┌─ src/smtp_server_example.erl:554 │555 229 │ {ok, State} | {stop, any(), State}.556 │ ╰── type variable 'State' is only used once (is unbound)557558559** (Mix) Could not compile dependency :gen_smtp, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile gen_smtp --force", update it with "mix deps.update gen_smtp" or clean it with "mix deps.clean gen_smtp"