Ghost FTP 2.1.1 RC18
Released: 24 September 2026
RC18 is a privacy, security and release-quality hardening candidate built on the RC17 single-window native desktop line.
Main changes
- Terminal inline-suggestion history is now process-memory only and is never written to WebView localStorage.
- Credential-looking shell commands are excluded from suggestion history even for the current session.
- Notification-center history is session-only and no longer persists raw diagnostic text in browser storage.
- Added central diagnostic redaction for credential query parameters, password/token assignments, sensitive CLI flags, Authorization/Bearer values, URL passwords, structured JSON credential fields and private-key blocks.
- App-level and workspace-level error boundaries use the same central redaction before logging diagnostic text.
- Startup migration removes legacy persisted terminal and notification history keys created by older release candidates.
- CI now rejects regressions that reintroduce persisted terminal/notification history or remove the required credential-redaction controls.
- Active README, feature, build-status, QA, roadmap and release-process documentation is refreshed so it no longer presents RC10–RC15 as the current product line.
- Preserves the RC17 one-window architecture, real progress-derived transfer telemetry, fail-closed CLI self-update policy and 7-surface × 3-viewport Windows native QA matrix.
Release validation
RC18 publication is allowed only from the exact approved source commit after all of these succeed:
- frontend typecheck and production build;
- i18n and single-window/UI/security regression checks;
- production npm dependency audit at high severity;
- Rust formatting, workspace check, tests and Clippy;
- real FTP, explicit FTPS and SFTP roundtrip E2E;
- Windows x64 native bundle and native-window visual QA;
- Linux x86-64 native binary, AppImage, DEB and RPM builds;
- RC18 source/documentation package generation.
RC18 is a pre-release candidate, not a stable/FINAL certification. Earlier release tags remain immutable.