64e4925fbb
Closes Trivy alerts #375 (sigstore CVE-2026-48815), #321 (@sigstore/core), #314 (tar) — npm@10 bundles the vulnerable sigstore 3.1.0; npm 11 ships the patched 4.x. Safe because this npm is CLI-only in the final image: runtime deps come from the builder stage's node_modules and the entrypoint runs node, not npm, so the install-behaviour issues that motivated the 10.x pin never run here. npm 11 requires Node >=22.9 — satisfied by node:22-alpine.