Ghost FTP 0.20.9
Ghost FTP 0.20.9 follows the published canonical 0.20.8 release.
Changes
- Adds a real desktop transfer-history CSV export backed by the persisted Rust transfer ledger.
- Routes the export through Transfer Center UI, Zustand state, Tauri IPC and the Rust backend instead of a UI-only placeholder.
- Neutralizes spreadsheet-formula prefixes in user/server-controlled CSV cells and omits raw backend error strings from the shareable export.
- Allows the verified stable GitHub package release to proceed without private updater-signing keys while deliberately omitting the in-app updater bundle in that mode.
- When updater signing is enabled, requires both Windows/Linux signatures plus the exact-version
latest.jsonand matching Update-Service package as an all-or-nothing verified set. - Verifies that the manifest embedded in the optional Update-Service archive is byte-identical to the separately published manifest.
- Extends source reachability from TypeScript into Rust crate module graphs and adds operational script reference checks.
- Expands CI syntax validation across Node/MJS and shell build/release utility scripts.
- Adds Android JVM unit coverage for cancellation, host normalization, invalid port handling, remote-path dot-segment rejection and root-delete protection;
testDebugUnitTestis now part of the canonical Android gate. - Refreshes active README, status, roadmap, audit, release and updater documentation for the 0.20.9 / previous 0.20.8 line.
- Keeps Android release semantics explicit:
com.ghostftp.androidproduction output remains unsigned unless a persistent production signing identity is intentionally configured; the debug-key-signed non-debuggable package remains an installable preview and is not described as production-signed.
Publication gate
The source version is not sufficient evidence of release completion. Publication remains blocked until the exact same head SHA passes Ghost FTP quality, Ghost FTP protocol E2E, Ghost FTP native build, Ghost FTP Android and Validate Windows hardening. Existing v0.20.8 tag/release history is immutable and must not be retargeted.