Bump Logback to 1.5.37 (CVE-2026-9828, CVE-2026-10532)

- fix(deps): logback 1.5.37 closes two HardenedObjectInputStream
  whitelist bypasses in logback-core (Object Injection via
  SimpleSocketServer/SimpleSSLSocketServer): CVE-2026-9828 (fixed
  in 1.5.33) and CVE-2026-10532 (fixed in 1.5.34). Full unit suite
  green (448 tests).