- Patched BoringSSL to fix CVE‑2026‑35189 memory allocation issue that could cause remote DoS during TLS handshakes.
- Removed Debian Bullseye (11) packaging, moved .changes and checksum signing into Bazel, and refreshed the Ubuntu build image.
- Published updated Docker images for Envoy v1.37.7.