From 84777cf2e4867715918bf2130bc272cebe3805e8 Mon Sep 17 00:00:00 2001 From: Austin McKinley <54160+amckinley@users.noreply.github.com> Date: Mon, 6 Jul 2026 10:31:57 -0700 Subject: [PATCH] build: bump Node to 24.18 for June 2026 security releases (#354) The June 18 2026 Node.js security releases fix several HIGH/MEDIUM CVEs on the 24.x line, with 24.17.0 as the first patched release. The service images were pinned to 24.15, below that line. Bump to 24.18-alpine3.23 (latest 24.x) to pick up the fixes, including: - CVE-2026-48618 (HIGH) TLS wildcard-depth auth bypass - CVE-2026-48933 (HIGH) WebCrypto AES integer overflow crash - CVE-2026-48928/48930/48934 (MEDIUM) TLS/SNI identity verification bypasses - CVE-2026-48619 (MEDIUM) unbounded HTTP/2 memory growth via ORIGIN frames Advisory: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases Co-authored-by: Claude Opus 4.8 (1M context) --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index a955231..ad01598 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ # NOTE there is an additional build stage below that should match -FROM node:24.15-alpine3.23 AS build +FROM node:24.18-alpine3.23 AS build RUN corepack enable @@ -17,7 +17,7 @@ RUN corepack prepare --activate RUN pnpm install --production --frozen-lockfile > /dev/null # Uses assets from build stage to reduce build size -FROM node:24.15-alpine3.23 +FROM node:24.18-alpine3.23 RUN apk add --update dumb-init -- 2.51.2