If I need node.js 20 I will just use the node:20-bookworm image.
As silly as it sounds, try running "snyk container test --print-deps" on that image, and look around for Node.
This approach works fine, but means that you might not be able to rely on most container security scanners to let you know when there's an issue.
At the end of they you need to keep an eye on file integrity, because of rootkits, config integrity…
Yeah there are many wats to approach to this… with its corresponding costs of course