bootstrap image: Go-stdlib CVEs reported against a prebuilt binary in node_modules (advisory scan)

With npm gone (1.0.1), the advisory image_scan_bootstrap job now reports 22 findings (21 HIGH, 1 CRITICAL), all Go stdlib CVEs (CVE-2025-68121, CVE-2025-61726, CVE-2025-61729, CVE-2026-25679, CVE-2026-27145, CVE-2026-32280, CVE-2026-32281, …) against a prebuilt Go binary shipped inside node_modules: app/node_modules/@esbuild-kit/core-utils/node_modules/@esbuild/linux-x64/bin/es- app/node_modules/@esbuild-kit/core-utils/node_modules/esbuild/bin/esbuild app/node_modules/drizzle-kit/node_modules/@esbuild/linux-x64/bin/esbuild — the esbuild platform binary that tsx depends on, compiled with Go 1.23.12.

This binary only runs during the one-shot bootstrap (transpiling the seed scripts) and never listens on a network, so the TLS/x509/net-url CVEs are not reachable, but the report is noise until the upstream binary is rebuilt with a patched Go.

Options: (a) bump tsx/esbuild when a release built with Go ≥ 1.25.11 lands; (b) precompile the seeds with tsc in the build stage so the bootstrap image needs no tsx/esbuild at all — then image_scan_bootstrap can become a hard gate like image_scan.

Job: https://gitlab.com/foxxcyber-oss/bedrock-rmf/-/pipelines/2797551376