Ghost FTP v0.30.21 — diagnostic privacy and FTP parser hardening
This version builds on verified public v0.30.20 without replacing the existing application, visual assets, or README layout.
Implemented source changes
- Windows/Linux / React diagnostics: Wholly discard untrusted diagnostic strings above 64 KiB before regexes execute. Redact before display truncation, hide unterminated private-key blocks and macOS-style private home paths.
- Desktop regression tests:
check-diagnostic-redaction.mjsexecutes the actual TypeScript redaction implementation and covers oversized responses, unclosed private keys, auth headers, query tokens, home paths and display truncation; it is part ofcheck:ui. - macOS Swift FTP Preview: Reject malformed EPSV passive-port replies containing extra trailing fields. Added dedicated Swift XCTest cases. FTPS and SFTP stay disabled on macOS until verified identity validation exists.
- Visual integrity: Preserve all seven real Windows README screenshots, their SHA256 provenance, gallery layout and all established branding. No fake server/transfer data.
Release acceptance
Six exact-commit PR workflows, six exact-commit merged-main workflows and verified canonical release artifacts must succeed before public publication. Full 75-screen installed-build pixel/click signoff remains pending.