Oh. As the creator and reluctant maintainer of npm's "ssh-keygen", this is awkward! First question: does this mean I won't be able to publish patches to the package? Why do I not want this package under my control? The original package simply calls spawn for your real `ssh-keygen` with the appropriate arguments. No real problem, (although there is very little value here). But a contributor added support for Windows b…
> "only" downloaded ~1600 times/week
This begs for an audit.