Moves the application pin to v26.08.11.1, which applies pending Debian security updates in the runtime image. This clears the openssl CVEs (CVE-2026-31789 CRITICAL plus several HIGH) that were failing the image-checks trivy gate; openssl moves from 3.5.4-1deb13u1 to 3.5.6-1deb13u2.