3 ms·
Oh. As the creator and reluctant maintainer of npm's "ssh-keygen", this is awkward! First question: does this mean I won't be able to publish patches to the pa
by evv 3y ago
Oh. As the creator and reluctant maintainer of npm's "ssh-keygen", this is awkward!
First question: does this mean I won't be able to publish patches to the package?
Why do I not want this package under my control? The original package simply calls spawn for your real `ssh-keygen` with the appropriate arguments. No real problem, (although there is very little value here). But a contributor added support for Windows by uploading opaque binary builds for Windows. While I have no reason to distrust the contributor, it is scary to be "responsible" for opaque executables that I did not personally produce.
So, what should I do with this package? Assuming npm lets me do anything?
Fortunately this package is "only" downloaded ~1600 times/week, miniscule for npm. If you are tempted to use ssh-keygen, I recommend you learn how to use execFile/spawn, and use the native program directly.
For context, I published this 10 years ago, as one of my earliest contributions to open source. I probably wouldn't have gone near any security-essential contributions if I had more experience at the time.