Nice, I forgot that one. BearSSL is one of only two TLS implementations (if I recall correctly) that wasn't vulnerable to the most recent Bleichenbacher attack variant.
That's correct, BearSSL and BoringSSL (Google's OpenSSL fork). Pornin is a bad-ass. But keep in mind that they were targeting C/C++ libraries, so we don't have telemetry on (for instance) Go's crypto/tls or whatever Rust is doing with ring.