- Upgrade Go builder to 1.24.10 and golang.org/x/crypto to v0.43.0, fixing CVE‑2025‑47913.
- Bugfixes: drop empty‑value labels in vmalert alerts, enforce retentionFilter duration < retentionPeriod, and apply maxDataSize limits to zstd‑encoded ingest requests.
- Add upgrade note: ensure retentionFilter duration is lower than retentionPeriod to avoid deployment failure.