- fix(security): use a safe 25 MiB default for
spool_afterwhen missing or invalid. - fix(security): prevent body lines like
--__proto__--\r\nfrom mutating Object.prototype - fix:
destroy()during a pending spool open now closes the late-arriving fd and removes the spool file - dep(eslint): bumped to latest