github bren-wp/Ghost-FTP v0.30.10
Ghost FTP 0.30.10

4 hours ago

Ghost FTP 0.30.10

Release date: 6 October 2026

Ghost FTP 0.30.10 advances the dedicated macOS Preview from read-only FTP browsing to real streamed file transfer.

Main changes

  • Adds real macOS plain-FTP file upload with STOR over an EPSV passive data connection.
  • Adds real macOS plain-FTP file download with RETR over an EPSV passive data connection.
  • Streams upload/download data in 64 KiB chunks instead of buffering whole files in memory.
  • Downloads into a sibling temporary .ghostftp-*.part file and only promotes it after the FTP server confirms transfer completion.
  • Uses the macOS open/save panels for explicit user-selected local file access and respects security-scoped URLs when provided by the system.
  • Rejects empty, traversal-style and CR/LF/NUL-injected remote transfer names before issuing FTP commands.
  • Fails the FTP session closed after an interrupted/ambiguous transfer so stale control-channel replies cannot be mistaken for later commands.
  • Refreshes the remote MLSD listing after a successful upload and exposes transfer state in the SwiftUI Preview.
  • Keeps the existing 8 MiB MLSD listing-memory bound and strict host/command input validation.
  • Updates the locked source-map-js build dependency from 1.2.1 to 1.2.2 so the release does not ship with the newly detected high-severity audit finding; no audit exception is introduced.
  • Corrects the development-audit classifier so lower-severity transitive advisories are not incorrectly promoted to high/critical; unknown high/critical findings remain release-blocking.

Explicit macOS Preview limits

  • The new upload/download implementation is for plain FTP only.
  • Explicit FTPS still requires a real AUTH TLS session with certificate and hostname validation before file operations.
  • SFTP still requires a real SSH/SFTP engine with host-key verification before authentication.
  • The macOS artifact remains an ad-hoc-signed development Preview, not a Developer ID signed/notarized production package.

Verification

Publication is allowed only from the exact release source SHA after all required gates succeed:

  • Ghost FTP quality
  • Ghost FTP protocol E2E
  • Ghost FTP native build
  • Ghost FTP Android
  • Validate Windows hardening
  • Ghost FTP macOS

Previous canonical release: 0.30.9.

Canonical metadata

  • Product version: 0.30.10
  • Build: 2026.10.06.2
  • Android versionCode: 301001
  • Channel: stable
  • Source of truth: root version.json

Don't miss a new Ghost-FTP release

NewReleases is sending notifications on new releases.