Hello,
Docker Hub currently reports GHSA-3ppc-4f35-3m26 (minimatch < 10.2.1) for node:24.x-alpine images.
Could you please confirm whether the bundled npm version in the current 24.x images includes minimatch >= 10.2.1?
If not, would it be possible to bump the bundled npm / dependency chain in an upcoming 24.x release so the image no longer flags this CVE?
Thank you.