Build log
host
workbench 0.0.18 · fail · run workbench-0.0.18-1791158693848
188 of 188 lines
1Resolving Hex dependencies...2Resolution completed in 0.776s3Unchanged:4 bamboo 2.2.05 bamboo_smtp 4.2.26 castore 1.0.217 certifi 2.15.08 circular_buffer 1.1.09 combine 0.10.010 confex 3.5.111 cowboy 2.19.012 cowboy_telemetry 0.4.013 cowlib 2.20.0 VULNERABLE!14 EEF-CVE-2026-43966 (MEDIUM)15 aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c16 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/217 https://osv.dev/vulnerability/EEF-CVE-2026-439661819 EEF-CVE-2026-43969 (LOW)20 aka: CVE-2026-43969, GHSA-g2wm-735q-3f5621 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/122 https://osv.dev/vulnerability/EEF-CVE-2026-4396923 db_connection 2.10.224 decimal 2.4.1 VULNERABLE!25 EEF-CVE-2026-32686 (MEDIUM)26 aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v27 Unbounded exponent in decimal enables unauthenticated DoS28 https://osv.dev/vulnerability/EEF-CVE-2026-3268629 deque 1.2.030 ecto 3.13.631 ecto_sql 3.13.532 ecto_term 0.0.133 elixir_make 0.10.034 enumerati 0.0.835 etso 0.1.636 ex2ms 1.7.037 ex_binance 0.0.1038 ex_bitmex 0.6.139 ex_bybit 0.0.140 ex_delta_exchange 0.0.341 ex_deribit 0.0.942 ex_ftx 0.0.1443 ex_gdax 0.2.044 ex_huobi 0.0.245 ex_okex 0.6.046 exconstructor 1.3.147 gen_smtp 1.2.048 gettext 0.19.149 hackney 1.25.0 VULNERABLE!50 EEF-CVE-2026-47071 (HIGH)51 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr52 SOCKS5 TLS upgrade ignores caller timeout in hackney53 https://osv.dev/vulnerability/EEF-CVE-2026-470715455 EEF-CVE-2026-47076 (MEDIUM)56 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq57 SSRF allowlist bypass via percent-encoded host in hackney58 https://osv.dev/vulnerability/EEF-CVE-2026-470765960 EEF-CVE-2026-47069 (LOW)61 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw262 CRLF injection in cookie domain/path options in hackney63 https://osv.dev/vulnerability/EEF-CVE-2026-470696465 EEF-CVE-2026-47075 (MEDIUM)66 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf67 CR/LF injection in query parameter in hackney68 https://osv.dev/vulnerability/EEF-CVE-2026-4707569 httpoison 1.8.270 idna 6.1.171 interactive_cmd 0.1.472 jason 1.4.573 juice 0.0.374 libcluster 3.5.075 mapail 1.0.276 maptu 1.0.077 metrics 1.0.178 mime 1.6.079 mimerl 1.5.080 murmur 1.0.481 navigator 0.0.882 nerves 2.0.0-pre.283 nerves_discovery 0.1.584 nerves_logging 0.2.485 nerves_runtime 0.13.1386 nerves_system_bbb 2.30.287 nerves_system_br 1.34.488 nerves_system_mangopi_mq_pro 0.17.289 nerves_system_qemu_aarch64 0.4.290 nerves_system_rpi0 2.1.291 nerves_system_rpi4 2.1.292 nerves_system_rpi5 2.1.293 nerves_system_trellis 0.5.094 nerves_system_x86_64 1.34.295 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.196 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.197 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.198 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.199 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1100 nerves_uevent 0.1.7101 notified 0.0.6102 notified_phoenix 0.0.7103 number 1.0.5104 ordered_nary_tree 0.0.4105 paged_query 0.0.2106 parse_trans 3.4.1107 phoenix 1.6.17108 phoenix_ecto 4.7.0109 phoenix_html 3.3.4110 phoenix_live_view 0.17.14 VULNERABLE!111 EEF-CVE-2026-64941 (LOW)112 aka: CVE-2026-64941, GHSA-36m4-rm57-3prf113 Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR114 https://osv.dev/vulnerability/EEF-CVE-2026-64941115 phoenix_pubsub 2.3.0116 phoenix_template 1.1.0117 phoenix_view 2.0.4118 plug 1.20.3119 plug_cowboy 2.9.0120 plug_crypto 1.2.5121 poison 4.0.1122 polymorphic_embed 1.10.0123 poolboy 1.5.2124 postgrex 0.22.4125 proper_case 1.3.1126 property_table 0.3.4127 ranch 2.3.0128 ring_logger 0.11.7129 schoolbus 0.0.3130 ssl_verify_fun 1.1.7131 stored 0.0.8132 stylish 0.0.9133 table_rex 3.2.0134 tablet 0.3.3135 tai 0.0.75136 tai_events 0.0.2137 telemetry 1.4.2138 telemetry_metrics 0.6.2139 telemetry_metrics_prometheus 1.1.0140 telemetry_metrics_prometheus_core 1.2.1141 telemetry_poller 1.3.0142 timex 3.7.9143 toolshed 0.5.0144 tzdata 1.2.2145 uboot_env 1.0.2146 unicode_util_compat 0.7.1147 vex 0.9.2148 websockex 0.4.3149 workbench 0.0.18150Found packages with security advisories, see above for details151All dependencies have been fetched152 warning: using single-quoted strings to represent charlists is deprecated.153 Use ~c"" if you indeed want a charlist or use "" instead.154 You may run "mix format --migrate" to change all single-quoted155 strings to use the ~c sigil and fix this warning.156 │157 21 │ defp elixirc_paths(:test), do: ['lib', 'test/support']158 │ ~159 │160 └─ /work/proj/deps/websockex/mix.exs:21:35161162 warning: using single-quoted strings to represent charlists is deprecated.163 Use ~c"" if you indeed want a charlist or use "" instead.164 You may run "mix format --migrate" to change all single-quoted165 strings to use the ~c sigil and fix this warning.166 │167 21 │ defp elixirc_paths(:test), do: ['lib', 'test/support']168 │ ~169 │170 └─ /work/proj/deps/websockex/mix.exs:21:42171172 warning: using single-quoted strings to represent charlists is deprecated.173 Use ~c"" if you indeed want a charlist or use "" instead.174 You may run "mix format --migrate" to change all single-quoted175 strings to use the ~c sigil and fix this warning.176 │177 22 │ defp elixirc_paths(_), do: ['lib']178 │ ~179 │180 └─ /work/proj/deps/websockex/mix.exs:22:31181182==> schoolbus183Compiling 2 files (.ex)184Generated schoolbus app185==> websockex186could not compile dependency :websockex, "mix compile" failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile websockex --force", update it with "mix deps.update websockex" or clean it with "mix deps.clean websockex"187==> nerves_compatibility_test188** (Mix) :elixirc_paths should be a list of string paths, got: [~c"lib"]