build: bump Node to 24.18 for June 2026 security releases

The June 18 2026 Node.js security releases fix several HIGH/MEDIUM CVEs
on the 24.x line, with 24.17.0 as the first patched release. The service
images were pinned to 24.15, below that line. Bump to 24.18-alpine3.23
(latest 24.x) to pick up the fixes, including:

- CVE-2026-48618 (HIGH) TLS wildcard-depth auth bypass
- CVE-2026-48933 (HIGH) WebCrypto AES integer overflow crash
- CVE-2026-48928/48930/48934 (MEDIUM) TLS/SNI identity verification bypasses
- CVE-2026-48619 (MEDIUM) unbounded HTTP/2 memory growth via ORIGIN frames

Advisory: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Austin McKinley
2026-07-05 21:20:04 -07:00
parent 79a16094f1
commit bf71c329c6
6 changed files with 9 additions and 9 deletions
+2 -2
View File
@@ -3,7 +3,7 @@
"version": "1.127.0",
"private": true,
"engines": {
"node": ">=24.15.0"
"node": ">=24.18.0"
},
"devEngines": {
"packageManager": {
@@ -13,7 +13,7 @@
},
"runtime": {
"name": "node",
"version": "^24.15.0",
"version": "^24.18.0",
"onFail": "download"
}
},