v3.1.8
Security-only release. Replaces apt ffmpeg 7.1.4 with multi-stage COPY from mwader/static-ffmpeg:8.1.1 to cover four 2026 CVEs that Debian trixie postponed: CVE-2026-30997, CVE-2026-30999, CVE-2026-6385, CVE-2026-40962. No code changes; binary lookup via shutil.which() so paths are agnostic. Multi-arch (amd64 + arm64) preserved.