build: bump Node to 24.18 for June 2026 security releases
The June 18 2026 Node.js security releases fix several HIGH/MEDIUM CVEs on the 24.x line, with 24.17.0 as the first patched release. The service images were pinned to 24.15, below that line. Bump to 24.18-alpine3.23 (latest 24.x) to pick up the fixes, including: - CVE-2026-48618 (HIGH) TLS wildcard-depth auth bypass - CVE-2026-48933 (HIGH) WebCrypto AES integer overflow crash - CVE-2026-48928/48930/48934 (MEDIUM) TLS/SNI identity verification bypasses - CVE-2026-48619 (MEDIUM) unbounded HTTP/2 memory growth via ORIGIN frames Advisory: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
+1
-1
@@ -5,7 +5,7 @@ WORKDIR /usr/src/social-app
|
||||
ENV DEBIAN_FRONTEND=noninteractive
|
||||
|
||||
# Node
|
||||
ENV NODE_VERSION=24.15.0
|
||||
ENV NODE_VERSION=24.18.0
|
||||
ENV NVM_DIR=/usr/share/nvm
|
||||
|
||||
# Go
|
||||
|
||||
Reference in New Issue
Block a user