Bump Logback to 1.5.37 (CVE-2026-9828, CVE-2026-10532) - fix(deps): logback 1.5.37 closes two HardenedObjectInputStream whitelist bypasses in logback-core (Object Injection via SimpleSocketServer/SimpleSSLSocketServer): CVE-2026-9828 (fixed in 1.5.33) and CVE-2026-10532 (fixed in 1.5.34). Full unit suite green (448 tests).