Build log
nerves_system_qemu_aarch64
workbench 0.0.18 · fail · run workbench-0.0.18-1791158693848
569 of 569 lines
1Resolving Hex dependencies...2Resolution completed in 0.623s3Unchanged:4 bamboo 2.2.05 bamboo_smtp 4.2.26 castore 1.0.217 certifi 2.15.08 circular_buffer 1.1.09 combine 0.10.010 confex 3.5.111 cowboy 2.19.012 cowboy_telemetry 0.4.013 cowlib 2.20.0 VULNERABLE!14 EEF-CVE-2026-43966 (MEDIUM)15 aka: CVE-2026-43966, GHSA-w4f7-4cxr-rv3c16 HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/217 https://osv.dev/vulnerability/EEF-CVE-2026-439661819 EEF-CVE-2026-43969 (LOW)20 aka: CVE-2026-43969, GHSA-g2wm-735q-3f5621 Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/122 https://osv.dev/vulnerability/EEF-CVE-2026-4396923 db_connection 2.10.224 decimal 2.4.1 VULNERABLE!25 EEF-CVE-2026-32686 (MEDIUM)26 aka: CVE-2026-32686, GHSA-rhv4-8758-jx7v27 Unbounded exponent in decimal enables unauthenticated DoS28 https://osv.dev/vulnerability/EEF-CVE-2026-3268629 deque 1.2.030 ecto 3.13.631 ecto_sql 3.13.532 ecto_term 0.0.133 elixir_make 0.10.034 enumerati 0.0.835 etso 0.1.636 ex2ms 1.7.037 ex_binance 0.0.1038 ex_bitmex 0.6.139 ex_bybit 0.0.140 ex_delta_exchange 0.0.341 ex_deribit 0.0.942 ex_ftx 0.0.1443 ex_gdax 0.2.044 ex_huobi 0.0.245 ex_okex 0.6.046 exconstructor 1.3.147 gen_smtp 1.2.048 gettext 0.19.149 hackney 1.25.0 VULNERABLE!50 EEF-CVE-2026-47071 (HIGH)51 aka: CVE-2026-47071, GHSA-gp9c-pm5m-5cxr52 SOCKS5 TLS upgrade ignores caller timeout in hackney53 https://osv.dev/vulnerability/EEF-CVE-2026-470715455 EEF-CVE-2026-47076 (MEDIUM)56 aka: CVE-2026-47076, GHSA-pj7v-xfvx-wmjq57 SSRF allowlist bypass via percent-encoded host in hackney58 https://osv.dev/vulnerability/EEF-CVE-2026-470765960 EEF-CVE-2026-47069 (LOW)61 aka: CVE-2026-47069, GHSA-mp55-p8c9-rfw262 CRLF injection in cookie domain/path options in hackney63 https://osv.dev/vulnerability/EEF-CVE-2026-470696465 EEF-CVE-2026-47075 (MEDIUM)66 aka: CVE-2026-47075, GHSA-j9wq-vxxc-94wf67 CR/LF injection in query parameter in hackney68 https://osv.dev/vulnerability/EEF-CVE-2026-4707569 httpoison 1.8.270 idna 6.1.171 interactive_cmd 0.1.472 jason 1.4.573 juice 0.0.374 libcluster 3.5.075 mapail 1.0.276 maptu 1.0.077 metrics 1.0.178 mime 1.6.079 mimerl 1.5.080 murmur 1.0.481 navigator 0.0.882 nerves 2.0.0-pre.283 nerves_discovery 0.1.584 nerves_logging 0.2.485 nerves_runtime 0.13.1386 nerves_system_bbb 2.30.287 nerves_system_br 1.34.488 nerves_system_mangopi_mq_pro 0.17.289 nerves_system_qemu_aarch64 0.4.290 nerves_system_rpi0 2.1.291 nerves_system_rpi4 2.1.292 nerves_system_rpi5 2.1.293 nerves_system_trellis 0.5.094 nerves_system_x86_64 1.34.295 nerves_toolchain_aarch64_nerves_linux_gnu 15.3.196 nerves_toolchain_armv6_nerves_linux_gnueabihf 15.3.197 nerves_toolchain_armv7_nerves_linux_gnueabihf 15.3.198 nerves_toolchain_riscv64_nerves_linux_gnu 15.3.199 nerves_toolchain_x86_64_nerves_linux_musl 15.3.1100 nerves_uevent 0.1.7101 notified 0.0.6102 notified_phoenix 0.0.7103 number 1.0.5104 ordered_nary_tree 0.0.4105 paged_query 0.0.2106 parse_trans 3.4.1107 phoenix 1.6.17108 phoenix_ecto 4.7.0109 phoenix_html 3.3.4110 phoenix_live_view 0.17.14 VULNERABLE!111 EEF-CVE-2026-64941 (LOW)112 aka: CVE-2026-64941, GHSA-36m4-rm57-3prf113 Open redirect in Phoenix.LiveView.validate_local_url!/2 via ASCII tab, LF and CR114 https://osv.dev/vulnerability/EEF-CVE-2026-64941115 phoenix_pubsub 2.3.0116 phoenix_template 1.1.0117 phoenix_view 2.0.4118 plug 1.20.3119 plug_cowboy 2.9.0120 plug_crypto 1.2.5121 poison 4.0.1122 polymorphic_embed 1.10.0123 poolboy 1.5.2124 postgrex 0.22.4125 proper_case 1.3.1126 property_table 0.3.4127 ranch 2.3.0128 ring_logger 0.11.7129 schoolbus 0.0.3130 ssl_verify_fun 1.1.7131 stored 0.0.8132 stylish 0.0.9133 table_rex 3.2.0134 tablet 0.3.3135 tai 0.0.75136 tai_events 0.0.2137 telemetry 1.4.2138 telemetry_metrics 0.6.2139 telemetry_metrics_prometheus 1.1.0140 telemetry_metrics_prometheus_core 1.2.1141 telemetry_poller 1.3.0142 timex 3.7.9143 toolshed 0.5.0144 tzdata 1.2.2145 uboot_env 1.0.2146 unicode_util_compat 0.7.1147 vex 0.9.2148 websockex 0.4.3149 workbench 0.0.18150* Getting workbench (Hex package)151* Getting nerves (Hex package)152* Getting ring_logger (Hex package)153* Getting toolshed (Hex package)154* Getting nerves_runtime (Hex package)155* Getting nerves_system_bbb (Hex package)156* Getting nerves_system_mangopi_mq_pro (Hex package)157* Getting nerves_system_qemu_aarch64 (Hex package)158* Getting nerves_system_rpi0 (Hex package)159* Getting nerves_system_rpi4 (Hex package)160* Getting nerves_system_rpi5 (Hex package)161* Getting nerves_system_trellis (Hex package)162* Getting nerves_system_x86_64 (Hex package)163* Getting nerves_system_br (Hex package)164* Getting nerves_toolchain_x86_64_nerves_linux_musl (Hex package)165* Getting nerves_toolchain_armv7_nerves_linux_gnueabihf (Hex package)166* Getting nerves_toolchain_aarch64_nerves_linux_gnu (Hex package)167* Getting nerves_toolchain_armv6_nerves_linux_gnueabihf (Hex package)168* Getting nerves_toolchain_riscv64_nerves_linux_gnu (Hex package)169* Getting nerves_logging (Hex package)170* Getting nerves_uevent (Hex package)171* Getting uboot_env (Hex package)172* Getting elixir_make (Hex package)173* Getting property_table (Hex package)174* Getting circular_buffer (Hex package)175* Getting interactive_cmd (Hex package)176* Getting nerves_discovery (Hex package)177* Getting tablet (Hex package)178* Getting decimal (Hex package)179* Getting deque (Hex package)180* Getting ecto_sql (Hex package)181* Getting enumerati (Hex package)182* Getting gettext (Hex package)183* Getting jason (Hex package)184* Getting libcluster (Hex package)185* Getting navigator (Hex package)186* Getting notified_phoenix (Hex package)187* Getting number (Hex package)188* Getting phoenix (Hex package)189* Getting phoenix_ecto (Hex package)190* Getting phoenix_html (Hex package)191* Getting phoenix_live_view (Hex package)192* Getting phoenix_pubsub (Hex package)193* Getting plug_cowboy (Hex package)194* Getting postgrex (Hex package)195* Getting schoolbus (Hex package)196* Getting stored (Hex package)197* Getting stylish (Hex package)198* Getting tai (Hex package)199* Getting telemetry (Hex package)200* Getting telemetry_metrics (Hex package)201* Getting telemetry_metrics_prometheus (Hex package)202* Getting telemetry_poller (Hex package)203* Getting timex (Hex package)204* Getting vex (Hex package)205* Getting combine (Hex package)206* Getting tzdata (Hex package)207* Getting telemetry_metrics_prometheus_core (Hex package)208* Getting confex (Hex package)209* Getting ecto (Hex package)210* Getting ecto_term (Hex package)211* Getting ex2ms (Hex package)212* Getting ex_binance (Hex package)213* Getting ex_bitmex (Hex package)214* Getting ex_bybit (Hex package)215* Getting ex_delta_exchange (Hex package)216* Getting ex_deribit (Hex package)217* Getting ex_ftx (Hex package)218* Getting ex_gdax (Hex package)219* Getting ex_huobi (Hex package)220* Getting ex_okex (Hex package)221* Getting httpoison (Hex package)222* Getting juice (Hex package)223* Getting murmur (Hex package)224* Getting paged_query (Hex package)225* Getting polymorphic_embed (Hex package)226* Getting poolboy (Hex package)227* Getting table_rex (Hex package)228* Getting tai_events (Hex package)229* Getting websockex (Hex package)230* Getting hackney (Hex package)231* Getting certifi (Hex package)232* Getting idna (Hex package)233* Getting metrics (Hex package)234* Getting mimerl (Hex package)235* Getting parse_trans (Hex package)236* Getting ssl_verify_fun (Hex package)237* Getting unicode_util_compat (Hex package)238* Getting mapail (Hex package)239* Getting maptu (Hex package)240* Getting poison (Hex package)241* Getting proper_case (Hex package)242* Getting exconstructor (Hex package)243* Getting db_connection (Hex package)244* Getting cowboy (Hex package)245* Getting cowboy_telemetry (Hex package)246* Getting plug (Hex package)247* Getting mime (Hex package)248* Getting plug_crypto (Hex package)249* Getting cowlib (Hex package)250* Getting ranch (Hex package)251* Getting castore (Hex package)252* Getting phoenix_view (Hex package)253* Getting phoenix_template (Hex package)254* Getting notified (Hex package)255* Getting bamboo (Hex package)256* Getting bamboo_smtp (Hex package)257* Getting etso (Hex package)258* Getting gen_smtp (Hex package)259* Getting ordered_nary_tree (Hex package)260Found packages with security advisories, see above for details261You have added/upgraded packages you could sponsor, run `mix hex.sponsor` to learn more262 warning: using single-quoted strings to represent charlists is deprecated.263 Use ~c"" if you indeed want a charlist or use "" instead.264 You may run "mix format --migrate" to change all single-quoted265 strings to use the ~c sigil and fix this warning.266 │267 21 │ defp elixirc_paths(:test), do: ['lib', 'test/support']268 │ ~269 │270 └─ /work/proj/deps_qemu_aarch64/websockex/mix.exs:21:35271272 warning: using single-quoted strings to represent charlists is deprecated.273 Use ~c"" if you indeed want a charlist or use "" instead.274 You may run "mix format --migrate" to change all single-quoted275 strings to use the ~c sigil and fix this warning.276 │277 21 │ defp elixirc_paths(:test), do: ['lib', 'test/support']278 │ ~279 │280 └─ /work/proj/deps_qemu_aarch64/websockex/mix.exs:21:42281282 warning: using single-quoted strings to represent charlists is deprecated.283 Use ~c"" if you indeed want a charlist or use "" instead.284 You may run "mix format --migrate" to change all single-quoted285 strings to use the ~c sigil and fix this warning.286 │287 22 │ defp elixirc_paths(_), do: ['lib']288 │ ~289 │290 └─ /work/proj/deps_qemu_aarch64/websockex/mix.exs:22:31291292==> nerves_system_br293Generated nerves_system_br app294==> combine295Compiling 6 files (.ex)296 warning: the variable "n" (context Combine.Parsers.Binary) is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator297 │298 26 │ <<bits::bitstring-size(n), rest::bitstring>> ->299 │ ~300 │301 └─ lib/combine/parsers/binary.ex:26:30: Combine.Parsers.Binary.bits_impl/2302303 warning: the variable "bits_size" (context Combine.Parsers.Binary) is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator304 │305 48 │ <<bits::bitstring-size(bits_size), rest::bitstring>> ->306 │ ~307 │308 └─ lib/combine/parsers/binary.ex:48:30: Combine.Parsers.Binary.bytes_impl/2309310 warning: the variable "size" (context Combine.Parsers.Binary) is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator311 │312 70 │ <<int::big-unsigned-size(size), rest::bitstring>> ->313 │ ~314 │315 └─ lib/combine/parsers/binary.ex:70:36: Combine.Parsers.Binary.uint_impl/3316317 warning: the variable "size" (context Combine.Parsers.Binary) is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator318 │319 77 │ <<int::little-unsigned-size(size), rest::bitstring>> ->320 │ ~321 │322 └─ lib/combine/parsers/binary.ex:77:39: Combine.Parsers.Binary.uint_impl/3323324 warning: the variable "size" (context Combine.Parsers.Binary) is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator325 │326 101 │ <<int::big-signed-size(size), rest::bitstring>> ->327 │ ~328 │329 └─ lib/combine/parsers/binary.ex:101:34: Combine.Parsers.Binary.int_impl/3330331 warning: the variable "size" (context Combine.Parsers.Binary) is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator332 │333 108 │ <<int::little-signed-size(size), rest::bitstring>> ->334 │ ~335 │336 └─ lib/combine/parsers/binary.ex:108:37: Combine.Parsers.Binary.int_impl/3337338 warning: the variable "size" (context Combine.Parsers.Binary) is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator339 │340 128 │ <<num::float-size(size), rest::bitstring>> ->341 │ ~342 │343 └─ lib/combine/parsers/binary.ex:128:25: Combine.Parsers.Binary.float_impl/2344345 warning: the variable "byte_size" (context Combine.Parsers.Text) is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator346 │347 432 │ <<^expected::binary-size(byte_size), rest::binary>> ->348 │ ~349 │350 └─ lib/combine/parsers/text.ex:432:34: Combine.Parsers.Text.string_impl/2351352 warning: the following clause is redundant:353354 defp word_of_impl(%Combine.ParserState{...} = state, _pattern)355356 it has type:357358 dynamic(%Combine.ParserState{status: :ok}), dynamic()359360 previous clauses have already matched on the following types:361362 %Combine.ParserState{status: :error}, term()363 %Combine.ParserState{status: :ok}, term()364365 │366 488 │ defp word_of_impl(%ParserState{status: :ok} = state, _pattern) do367 │ ~368 │369 └─ lib/combine/parsers/text.ex:488:8: Combine.Parsers.Text.word_of_impl/2370371Generated combine app372==> mime373Compiling 2 files (.ex)374Generated mime app375==> circular_buffer376Compiling 1 file (.ex)377Generated circular_buffer app378==> schoolbus379Compiling 2 files (.ex)380Generated schoolbus app381==> poison382Compiling 4 files (.ex)383 warning: using single-quoted strings to represent charlists is deprecated.384 Use ~c"" if you indeed want a charlist or use "" instead.385 You may run "mix format --migrate" to change all single-quoted386 strings to use the ~c sigil and fix this warning.387 │388 127 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do389 │ ~390 │391 └─ lib/poison/encoder.ex:127:31392393 warning: using single-quoted strings to represent charlists is deprecated.394 Use ~c"" if you indeed want a charlist or use "" instead.395 You may run "mix format --migrate" to change all single-quoted396 strings to use the ~c sigil and fix this warning.397 │398 127 │ for {char, seq} <- Enum.zip('"\\\n\t\r\f\b', '"\\ntrfb') do399 │ ~400 │401 └─ lib/poison/encoder.ex:127:48402403 warning: using single-quoted strings to represent charlists is deprecated.404 Use ~c"" if you indeed want a charlist or use "" instead.405 You may run "mix format --migrate" to change all single-quoted406 strings to use the ~c sigil and fix this warning.407 │408 174 │ when char <= 0x1F or char in '"\\' do409 │ ~410 │411 └─ lib/poison/encoder.ex:174:37412413 warning: using single-quoted strings to represent charlists is deprecated.414 Use ~c"" if you indeed want a charlist or use "" instead.415 You may run "mix format --migrate" to change all single-quoted416 strings to use the ~c sigil and fix this warning.417 │418 94 │ when char in '-0123456789' do419 │ ~420 │421 └─ lib/poison/parser.ex:94:21422423 warning: using single-quoted strings to represent charlists is deprecated.424 Use ~c"" if you indeed want a charlist or use "" instead.425 You may run "mix format --migrate" to change all single-quoted426 strings to use the ~c sigil and fix this warning.427 │428 189 │ when char in '123456789' do429 │ ~430 │431 └─ lib/poison/parser.ex:189:21432433 warning: using single-quoted strings to represent charlists is deprecated.434 Use ~c"" if you indeed want a charlist or use "" instead.435 You may run "mix format --migrate" to change all single-quoted436 strings to use the ~c sigil and fix this warning.437 │438 205 │ defp number_exp(<<e>> <> rest, frac, pos, acc) when e in 'eE' do439 │ ~440 │441 └─ lib/poison/parser.ex:205:60442443 warning: using single-quoted strings to represent charlists is deprecated.444 Use ~c"" if you indeed want a charlist or use "" instead.445 You may run "mix format --migrate" to change all single-quoted446 strings to use the ~c sigil and fix this warning.447 │448 238 │ when char in '0123456789' do449 │ ~450 │451 └─ lib/poison/parser.ex:238:21452453 warning: using single-quoted strings to represent charlists is deprecated.454 Use ~c"" if you indeed want a charlist or use "" instead.455 You may run "mix format --migrate" to change all single-quoted456 strings to use the ~c sigil and fix this warning.457 │458 246 │ defp number_digits_count(<<char>> <> rest, acc) when char in '0123456789' do459 │ ~460 │461 └─ lib/poison/parser.ex:246:64462463 warning: using single-quoted strings to represent charlists is deprecated.464 Use ~c"" if you indeed want a charlist or use "" instead.465 You may run "mix format --migrate" to change all single-quoted466 strings to use the ~c sigil and fix this warning.467 │468 270 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do469 │ ~470 │471 └─ lib/poison/parser.ex:270:31472473 warning: using single-quoted strings to represent charlists is deprecated.474 Use ~c"" if you indeed want a charlist or use "" instead.475 You may run "mix format --migrate" to change all single-quoted476 strings to use the ~c sigil and fix this warning.477 │478 270 │ for {seq, char} <- Enum.zip('"\\ntr/fb', '"\\\n\t\r/\f\b') do479 │ ~480 │481 └─ lib/poison/parser.ex:270:44482483 warning: using single-quoted strings to represent charlists is deprecated.484 Use ~c"" if you indeed want a charlist or use "" instead.485 You may run "mix format --migrate" to change all single-quoted486 strings to use the ~c sigil and fix this warning.487 │488 277 │ when a1 in 'dD' and a2 in 'dD' and b1 in '89abAB' and489 │ ~490 │491 └─ lib/poison/parser.ex:277:24492493 warning: using single-quoted strings to represent charlists is deprecated.494 Use ~c"" if you indeed want a charlist or use "" instead.495 You may run "mix format --migrate" to change all single-quoted496 strings to use the ~c sigil and fix this warning.497 │498 277 │ when a1 in 'dD' and a2 in 'dD' and b1 in '89abAB' and499 │ ~500 │501 └─ lib/poison/parser.ex:277:39502503 warning: using single-quoted strings to represent charlists is deprecated.504 Use ~c"" if you indeed want a charlist or use "" instead.505 You may run "mix format --migrate" to change all single-quoted506 strings to use the ~c sigil and fix this warning.507 │508 277 │ when a1 in 'dD' and a2 in 'dD' and b1 in '89abAB' and509 │ ~510 │511 └─ lib/poison/parser.ex:277:54512513 warning: using single-quoted strings to represent charlists is deprecated.514 Use ~c"" if you indeed want a charlist or use "" instead.515 You may run "mix format --migrate" to change all single-quoted516 strings to use the ~c sigil and fix this warning.517 │518 334 │ defp skip_whitespace(<<char>> <> rest, pos) when char in '\s\n\t\r' do519 │ ~520 │521 └─ lib/poison/parser.ex:334:60522523 warning: Application.get_env/2 is discouraged in the module body, use Application.compile_env/3 instead524 │525 42 │ if Application.get_env(:poison, :native) do526 │ ~527 │528 └─ lib/poison/parser.ex:42:18: Poison.Parser (module)529530 warning: use Bitwise is deprecated. import Bitwise instead531 │532 46 │ use Bitwise533 │ ~~~~~~~~~~~534 │535 └─ lib/poison/parser.ex:46: Poison.Parser (module)536537 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator538 │539 240 │ <<digits::binary-size(count), rest::binary>> = string540 │ ~541 │542 └─ lib/poison/parser.ex:240:27: Poison.Parser.number_digits/2543544 warning: the variable "count" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator545 │546 266 │ <<chunk::binary-size(count), rest::binary>> = string547 │ ~548 │549 └─ lib/poison/parser.ex:266:26: Poison.Parser.string_continue/3550551 warning: use Bitwise is deprecated. import Bitwise instead552 │553 117 │ use Bitwise554 │ ~~~~~~~~~~~555 │556 └─ lib/poison/encoder.ex:117: Poison.Encoder.BitString (module)557558 warning: the variable "size" is accessed inside size(...) of a bitstring but it was defined outside of the match. You must precede it with the pin operator559 │560 169 │ <<chunk::binary-size(size), rest::binary>> = string561 │ ~562 │563 └─ lib/poison/encoder.ex:169:26: Poison.Encoder.BitString.escape/2564565Generated poison app566==> websockex567could not compile dependency :websockex, "mix compile" failed. Errors may have been logged above. You can recompile this dependency with "mix deps.compile websockex --force", update it with "mix deps.update websockex" or clean it with "mix deps.clean websockex"568==> nerves_compatibility_test569** (Mix) :elixirc_paths should be a list of string paths, got: [~c"lib"]