mirror of
https://github.com/trailofbits/dropkit
synced 2026-06-21 14:11:54 +00:00
9895dd9d5e
Replace manual file parsing with ssh-keygen -R which properly handles both hashed (|1|...) and unhashed entries. macOS and many Linux systems use HashKnownHosts by default, making the previous implementation unable to remove entries. Changes: - Use ssh-keygen -R for each hostname instead of parsing the file - Detect successful removal via "updated" in stdout - Backup files are now .old (ssh-keygen default) instead of .bak - Bracketed entries ([host]:port) now require exact format Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>