v0.11.1
- ci(release): gate container-image scans on critical (base-image OS CVEs are unfixable churn; criticals still block, source-tree scans stay on high). - build(scanner-bridge): multi-stage image drops build toolchain (gcc/libgit2-dev/ libffi-dev/pkg-config) from the runtime layer, removing ~40 linux-libc-dev kernel-header CVEs and libssh2 CVE-2026-7598 (9.1). Validated by full e2e. Carries the v0.11.0 token-scope enforcement (admin:read/write + proxy:fetch).