Skip to content

Ghost FTP 0.30.13

Choose a tag to compare

@github-actions github-actions released this 08 Oct 21:30
ddebaa5

Ghost FTP 0.30.13 — release candidate

Release date: 8 October 2026 (planned; publication must be verified in GitHub Releases).

Previous merged source version: 0.30.12. Previous published canonical version: 0.30.10. Neither 0.30.11 nor 0.30.12 was published; their CI-verified changes remain in this source candidate.

macOS functional and security corrections

  • The real plain-FTP RETR and STOR commands now interpolate the actual validated server filename instead of sending literal placeholders.
  • Temporary download files now use a destination-derived name plus a unique UUID. They are promoted only after successful FTP completion.
  • MLSD filenames from untrusted servers are validated before use. Traversal and control-command injection candidates are filtered.
  • FTP control responses are bounded to 256 KiB to prevent unbounded control-channel memory use.
  • Swift regression tests and macOS production-contract guards enforce these corrections.

Publication integrity

  • A previous merged development source is no longer mistaken for a published GitHub Release.
  • Release preflight checks the exact latest public release against previousPublishedVersion (0.30.10), while source progression checks still require previousVersion (0.30.12).
  • Canonical publication still requires exact-SHA successful quality, protocol, Android, Windows hardening, macOS and native-build gates plus the full asset/checksum verification.

Remaining blockers before four production-final applications

  • macOS encrypted FTPS and SSH/SFTP filesystem engines with real certificate, hostname and host-key verification.
  • Apple Developer ID signing, notarization and end-user install/upgrade validation.
  • Android persistent production signing and cross-release upgrade verification; the current production APK is explicitly unsigned.
  • Broader Linux distro/desktop-environment acceptance and Android transfer-queue parity.

Do not claim complete four-platform feature parity or stable macOS/Android installation until these requirements are implemented and tested.

Metadata

  • Source version: 0.30.13
  • Previous source: 0.30.12
  • Previous published: 0.30.10
  • Build: 2026.10.08.1
  • Android versionCode: 301301
  • Channel: stable (release publication remains gated)