Ghost FTP 0.20.5
Release cycle: 0.20.5 patch release candidate
Cycle date: 1 October 2026
0.20.5 follows published 0.20.4. This document does not assert publication: only an immutable v0.20.5 GitHub Release at the verified source SHA with the required assets establishes the release.
Changes in this cycle
Android SFTP credential API hardening
- Replaced JSch's deprecated String password setter with
Session.setPassword(byte[]). - Converts the in-memory session password to UTF-8 only for the handoff.
- Zeroes the temporary byte array immediately after JSch copies it.
- Preserves the existing policy that Activity state never persists passwords or authenticated sessions.
Android 15 edge-to-edge correctness
- Removes direct Activity calls to deprecated
statusBarColorandnavigationBarColor. - On API 35+, applies
WindowInsets.Type.systemBars()to the programmatic root layout before users interact with the app. - Keeps Ghost FTP content out from under the enforced Android 15 system bars while retaining the dark application background.
- Adds an API 35 theme variant that keeps light system icons without deprecated system-bar color resources.
- Keeps the existing pre-API-35 theme behavior for Android 8 through Android 14.
Regression protection
- Android production-contract checks require the byte-array JSch password path and temporary-buffer cleanup.
- Contract checks reject reintroduction of the deprecated String password API and direct Activity system-bar color setters.
- Contract checks require API 35 system-bar inset handling and the API 35 theme override.
Publication requirements
The exact source intended for v0.20.5 must pass Ghost FTP quality, Ghost FTP protocol E2E, Ghost FTP native build, Ghost FTP Android and Validate Windows hardening on the same head SHA.
The canonical release must contain non-empty Windows portable/NSIS/MSI assets, Linux binary/AppImage/DEB/RPM assets, Android unsigned-production/installable-preview artifacts, source/documentation archives, native-QA evidence and SHA-256 checksums.
Stable status
0.20.5 remains in the pre-1.0 version train. Passing automated release gates does not by itself claim 1.0/FINAL product acceptance.