v2.3.5 (Patch — security)
- Security: bump build-time dependency
picomatchfrom 2.3.1 to 2.3.2 (#94) to address CVE-2026-33671 and CVE-2026-33672. The dependency is dev-only (transitive oftailwindcss, used at CSS build time) — runtime image and end-user installations are not exposed, but the bump keeps SCA scanners and CI clean. - Security: bump runtime dependency
pyopensslfrom 25.3.0 to 26.0.0 (#86). Routine maintenance — no known CVEs at the previous pin, but the new version closes a moderate-severity advisory in upstream OpenSSL bindings and is what fresh installs get by default.