rube

Build log

host

rube 0.1.0 · fail · run rube-0.1.0-1791092399440
179 of 179 lines
1Resolving Hex dependencies...2Resolution completed in 0.416s3Unchanged:4  bamboo 2.2.05  bamboo_smtp 4.2.26  certifi 2.15.07  circular_buffer 1.1.08  confex 3.5.19  cowboy 2.19.010  cowboy_telemetry 0.3.111  cowlib 2.20.0 VULNERABLE!12    EEF-CVE-2026-43966 (MEDIUM)13    aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c14    HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/215    https://osv.dev/vulnerability/EEF-CVE-2026-439661617    EEF-CVE-2026-43969 (LOW)18    aka: CVE-2026-43969, GHSA-g2wm-735q-3f5619    Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/120    https://osv.dev/vulnerability/EEF-CVE-2026-4396921  db_connection 2.10.222  decimal 2.4.1 VULNERABLE!23    EEF-CVE-2026-32686 (MEDIUM)24    aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v25    Unbounded exponent in decimal enables unauthenticated DoS26    https://osv.dev/vulnerability/EEF-CVE-2026-3268627  deque 1.2.028  earmark_parser 1.4.4629  ecto 3.13.630  ecto_sql 3.13.531  elixir_make 0.10.032  enumerati 0.0.833  ethereumex 0.7.134  etso 0.1.635  ex_abi 0.5.1636  ex_doc 0.40.437  ex_keccak 0.6.038  expo 1.1.139  exw3 0.6.140  gen_smtp 1.2.041  gettext 0.26.242  hackney 1.25.0 VULNERABLE!43    EEF-CVE-2026-47071 (HIGH)44    aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr45    SOCKS5 TLS upgrade ignores caller timeout in hackney46    https://osv.dev/vulnerability/EEF-CVE-2026-470714748    EEF-CVE-2026-47076 (MEDIUM)49    aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq50    SSRF allowlist bypass via percent-encoded host in hackney51    https://osv.dev/vulnerability/EEF-CVE-2026-470765253    EEF-CVE-2026-47069 (LOW)54    aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw255    CRLF injection in cookie domain/path options in hackney56    https://osv.dev/vulnerability/EEF-CVE-2026-470695758    EEF-CVE-2026-47075 (MEDIUM)59    aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf60    CR/LF injection in query parameter in hackney61    https://osv.dev/vulnerability/EEF-CVE-2026-4707562  httpoison 1.8.263  idna 6.1.164  interactive_cmd 0.1.465  jason 1.4.566  juice 0.0.367  makeup 1.2.368  makeup_elixir 1.0.169  makeup_erlang 1.1.070  master_proxy 0.1.4 RETIRED!71    (deprecated) Development has moved to main_proxy72  metrics 1.0.173  mime 1.6.074  mimerl 1.5.075  navigator 0.0.576  nerves 2.0.0-pre.277  nerves_discovery 0.1.578  nerves_logging 0.2.479  nerves_runtime 0.13.1380  nerves_system_bbb 2.30.281  nerves_system_br 1.34.482  nerves_system_mangopi_mq_pro 0.17.283  nerves_system_qemu_aarch64 0.4.284  nerves_system_rpi0 2.1.285  nerves_system_rpi4 2.1.286  nerves_system_rpi5 2.1.287  nerves_system_trellis 0.5.088  nerves_system_x86_64 1.34.289  nerves_toolchain_aarch64_nerves_linux_gnu 15.3.190  nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.191  nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.192  nerves_toolchain_riscv64_nerves_linux_gnu 15.3.193  nerves_toolchain_x86_64_nerves_linux_musl 15.3.194  nerves_uevent 0.1.795  nimble_parsec 1.4.296  notified 0.0.697  notified_phoenix 0.0.698  paged_query 0.0.299  parse_trans 3.4.1100  phoenix 1.5.15 VULNERABLE!101    GHSA-p8f7-22gq-m7j9 (HIGH)102    aka: CVE-2022-42975103    Phoenix before 1.6.14 mishandles check_origin wildcarding104    https://osv.dev/vulnerability/GHSA-p8f7-22gq-m7j9105  phoenix_ecto 4.7.0106  phoenix_html 2.14.3 VULNERABLE!107    GHSA-5g2h-9x5v-5h3x (MEDIUM)108    aka: CVE-2021-46871, GHSA-j3gg-r6gp-95q2109    phoenix_html allows Cross-site Scripting in HEEx class attributes110    https://osv.dev/vulnerability/GHSA-5g2h-9x5v-5h3x111  phoenix_live_dashboard 0.4.0112  phoenix_live_react 0.5.0113  phoenix_live_view 0.15.7 VULNERABLE!114    EEF-CVE-2026-64941 (LOW)115    aka: CVE-2026-64941, GHSA-36m4-rm57-3prf116    Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR117    https://osv.dev/vulnerability/EEF-CVE-2026-64941118  phoenix_pubsub 2.3.0119  plug 1.20.3120  plug_cowboy 2.9.0121  plug_crypto 1.2.5122  poolboy 1.5.2123  postgrex 0.22.4124  proper_case 1.3.1125  property_table 0.3.4126  ranch 2.3.0127  ring_logger 0.11.7128  rube 0.1.0 RETIRED!129    (invalid) invalid130  rustler 0.38.0131  slurp 0.0.12132  slurpee 0.0.13133  ssl_verify_fun 1.1.7134  stored 0.0.8135  stylish 0.0.6136  table_rex 3.2.0137  tablet 0.3.3138  telemetry 0.4.3139  telemetry_metrics 0.6.2140  telemetry_metrics_prometheus 1.1.0141  telemetry_metrics_prometheus_core 1.2.1142  telemetry_poller 0.5.1143  toolshed 0.5.0144  uboot_env 1.0.2145  unicode_util_compat 0.7.1146Found retired packages, see above for details147Found packages with security advisories, see above for details148All dependencies have been fetched149===> Analyzing applications...150===> Compiling gen_smtp151     ┌─ src/gen_smtp_server_session.erl:152     │153 401 │          case catch Module:code_change(OldVsn, CallbackState, Extra) of154     │               ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.155Compile directive 'nowarn_deprecated_catch' can be used to suppress156warnings in selected modules.157158     ┌─ src/gen_smtp_server_session.erl:159     │160 574 │                              crypto:start(),161     │                              ╰── Warning: crypto:start/0 is deprecated; use application:start(crypto) instead162163164     ┌─ src/gen_smtp_client.erl:165     │166 757 │                  catch smtp_socket:to_ssl_client(167     │                  ╰── Warning: 'catch ...' is deprecated; please use 'try ... catch ... end' instead.168Compile directive 'nowarn_deprecated_catch' can be used to suppress169warnings in selected modules.170171172===> Compiling src/smtp_server_example.erl failed173     ┌─ src/smtp_server_example.erl:174     │175 296 │      {ok, State} | {stop, any(), State}.176     │           ╰── type variable 'State' is only used once (is unbound)177178179** (Mix) Could not compile dependency :gen_smtp, "/home/nerves/.mix/elixir/1-20-otp-29/rebar3 bare compile --paths /work/proj/_build/host/lib/*/ebin" command failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile gen_smtp --force", update it with "mix deps.update gen_smtp" or clean it with "mix deps.clean gen_smtp"