Hi,
Docker Hub currently reports CVE-2026-26960 affecting tar < 7.5.8 for node:24.x-alpine images.
Could you please confirm whether the npm version bundled in the current 24.x-alpine images includes tar >= 7.5.8?
If not, would it be possible to bump the bundled npm / dependency chain in an upcoming 24.x release so that this CVE is no longer reported for the image?
Thank you.