Differences
This shows you the differences between the selected revisions of the page.
| history 2007-10-26 | history 2026-08-26 (current) | ||
| Line 1: | Line 1: | ||
| ====== Recent Version History ====== | ====== Recent Version History ====== | ||
| - | This is list of changes for each release of WinSCP. See also [[project_history|project history]]. | + | This is a full list of changes for each release of WinSCP. See also [[project_history|Project history]] and [[incompatible_changes|Incompatible changes between versions]]. |
| - | ===== Not Released Yet ===== | + | ===== [[6.8]] 6.8 (not released yet) ((2026-08-22)) ===== |
| - | === 2007-10-16 === | + | |
| - | * Speed limit can be actually set in KiB/s. | + | |
| - | * Speed limit can be set for background transfers. | + | |
| - | * Transfer settings were removed from transfer options dialog to simplify it. The settings can be changed by selecting transfer settings preset or by invoking custom transfer settings dialog (the same way as for synchronization). | + | |
| - | * More than one host key for a host may be accepted. | + | |
| - | * It is possible to cancel connection attempts of background transfer. | + | |
| - | * Proxy settings to check for updates can be automatically detected from system and IE settings. | + | |
| - | * When synchronized browsing is on and entered directory does not exist in an opposite directory, WinSCP offers to create it. | + | |
| - | * Added several switches to scripting commands to extend their capabilities with functionality available in GUI already: ''/mirror'' for ''synchronize'', ''/delete'' for ''synchronize'' and ''keepuptodate'' (obsoletes option ''synchdelete''), ''/delete'' to ''get'' and ''put'', ''/timeout'' and ''/privatekey'' to ''open''. | + | |
| - | * Added switch ''/hostkey'' to command-line and ''open'' script command to automatically accept host keys with given fingerprint. | + | |
| - | * During resumable transfers, the destination file is not removed (if present) until the transfer actually finishes. | + | |
| - | * Transfer and session toolbars automatically stretches to right window edge. | + | |
| - | * Command line panel is toolbar (can be docked elsewhere). | + | |
| - | * Address and command line drop down boxes follow the toolbar style. | + | |
| - | * On Explorer-like interface, path on address toolbar is editable. | + | |
| - | * //KiB// is used instead of //KB// for kilobyte. | + | |
| - | * Estimated time is shown instead of elapsed time in queue list. | + | |
| - | * //Open in PuTTY// makes PuTTY use Telnet or SSH session for FTP sessions in WinSCP. | + | |
| - | * Host key confirmation dialog has an option to copy the key into clipboard. | + | |
| - | * //Server does not use UTF-8// changed to //UTF-8 encoding for filenames// and moved to //Environment// tab, as it is used also by FTP protocol. | + | |
| - | * //Timezone offset// moved to //Environment// tab, as it is used also by FTP protocol. | + | |
| - | * ''Shift-Del'' deletes to recycle bin, if deletion to recycle bin is disabled, and vice versa. | + | |
| - | * Opening bookmarks does not trigger synchronized browsing anymore. | + | |
| - | * It is possible to optionally overwrite stored password with new one, if authentication with original stored password fails. | + | |
| - | * When saving current session with password, warning is displayed. | + | |
| - | * When saving session with password, option is given not to store the password. | + | |
| - | * //Edit link// function is available in context menu of remote symbolic links. | + | |
| - | * Size of directory change cache is limited. | + | |
| - | * Error messages of background transfer are actually presented as errors. | + | |
| - | * Initial size of Commander-like window is increased. | + | |
| - | * Improved initial placing of Commander-like window. | + | |
| - | * Improved ''call'' command description with respect to FTP protocol. | + | |
| - | * ''ftp'' protocol added to command-line syntax help. | + | |
| - | * Change: Transfer option //Preserve read-only// is off by default. | + | |
| - | ===== 4.0.5 ===== | + | ··* Word wrapping in the internal editor can be toggled from toolbar menu. [[bug>2451]] |
| - | === 2007-10-24 === | + | |
| - | ··* With FTP protocol, errors when parsing file permissions in directory listing are ignored. | + | |
| - | * Reading/writing INI files is faster. | + | |
| - | * Hostkey of tunneled session is verified against target session of tunnel. | + | |
| - | * When opening session in PuTTY, defaults for session options not set by WinSCP are loaded from //Default settings// of PuTTY. | + | |
| - | · * Increased maximal length of username. | + | |
| - | * Full system error is reported when writing of local file fails. | + | |
| - | * Sample custom command //Execute// changed to ''./!'' (from ''!''). | + | |
| - | * When parsing directory listing, plus sign after permissions, separated by space, is silently ignored. | + | |
| - | * When uploading to symbolic link with SFTP protocol, resuming is disabled to preserve the link. | + | |
| - | * Bug fix: Automatic reconnect in scripting was not working. | + | |
| - | * Bug fix: When reading of local file failed, while uploading with SFTP protocol, file transfer was interrupted without reporting any error. | + | |
| - | * Bug fix: When file transfer failed with FTP protocol, whole batch was interrupted, without an option to retry or skip the file transfer. | + | |
| - | * Bug fix: Failure when parsing of directory listing failed with FTP protocol. | + | |
| - | * Bug fix: Background color of directory tree icons has not reflected session color. | + | |
| - | * Bug fix: Removed dependency on ''netapi32.dll'' (not present on Windows 95/98/ME). | + | |
| - | * Bug fix: It was not possible to upload file opened in another application with FTP protocol. | + | |
| - | * Bug fix: Missing GSSAPI was incorrectly reported, even when SSPI with GSSAPI support was present. | + | |
| - | * Bug fix: Workaround for occasional bug when opening some dialogs. | + | |
| - | ===== 4.0.4 ===== | + | ===== [[6.6.3]] 6.6.3 (not released yet) ((2026-08-26)) ===== |
| - | === 2007-09-02 === | + | |
| - | * Fallback to simple FTP ''LIST'' command, when ''LIST -a'039; fails. | + | |
| - | * Workaround for bug in Windows Vista preventing selection of files with keyboard. | + | |
| - | · * Offline network drives are not scanned on startup to prevent long delays before a main window is shown. | + | |
| - | · * Improved security when handling URL's (from web browser). | + | |
| - | * Bug fix: When connection was broken during automatic transfers, program stalled for few seconds. | + | |
| - | * Bug fix: Instability the connection was dropped while keep remote directory up to date function was running. | + | |
| - | * Bug fix: Malformed prompt for username in scripting. | + | |
| - | * Bug fix: Second opened session with enabled SSH tunnel (with automatic selection of tunnel port) actually used the existing tunnel of the first session. | + | |
| - | ··* Bug fix: Memory leak when SSH connection is refused. | + | |
| - | * Bug fix: When username is not specified on login dialog, password typing is revealed on authentication dialog. | + | |
| + | * Translations completed: Belarusian, Brazilian Portuguese, Catalan, Croatian, Czech, Danish, Dutch, Finnish, French, German, Hungarian, Italian, Japanese, Korean, Lithuanian, Macedonian, Polish, Portuguese, Romanian, Russian, Serbian, Simplified Chinese, Slovak, Slovenian, Spanish, Swedish, Tamil, Traditional Chinese and Turkish. | ||
| + | * Some parts of GUI (panel headers, scrollbars, buttons, checkboxes) show dark in dark theme even when system-wide app theme is light. | ||
| + | * SSH core and private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. \\ It brings the following change: | ||
| + | * Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] | ||
| + | * Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] | ||
| + | * Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] | ||
| + | * Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] | ||
| + | * Bundled SSH private key tools (PuTTYgen and Pageant) are 64-bit. | ||
| + | * On Windows 11, using system dark tab theme, that uses different shades for active and disabled/disconnected tabs. [[bug>2452]] | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.5.8. | ||
| + | * XML parser upgraded to Expat 2.8.3. | ||
| + | * Source code package build script supports 64-bit target. | ||
| + | * 64-bit build is identified in version information. | ||
| + | * Resolving version of pwsh installed with MSIX. | ||
| + | * Thirdparty information from the About dialog can be copied to the clipboard even when the browser control malfunctions. | ||
| + | * Bug fix: No error is shown when connection fails. | ||
| + | * Bug fix: ''x-name'' URL parameter was incorrectly decoded | ||
| + | * Bug fix: Incorrect number validation. | ||
| + | * Bug fix: Some controls (notably list view headers) do not correctly apply dark mode in 64-bit build. [[bug>2453]] | ||
| + | * Bug fix: 64-bit build did not identify its system to be 64-bit, what among other prevented it from identifying 64-bit COM registrations. | ||
| - | ===== 4.0.3 ===== | + | ===== [[6.6.2]] 6.6.2 RC ((2026-06-17)) ===== |
| - | === 2007-07-12 === | + | |
| - | * Mask ''*.php*'039; in default text file mask is replaced with ''*.php'' and ''*.php3''. | + | |
| - | * Subdirectories of current directory are not scanned for purpose of displaying in tree view when the tree view is hidden. | + | |
| - | ··* Bug fix: Once any transfer is done while keep remote directory up to date is running, its dialog cannot be minimized anymore. | + | |
| - | · * Bug fix: Failure when automatically reconnecting the session from script with ''option batch continue''. | + | |
| - | ===== [[4.0.2]] 4.0.2 beta ===== | + | ··* Experimental 64-bit version of WinSCP. [[bug>618]] |
| - | === 2007-05-29 === | + | * Optionally not showing error message when connection is lost while idle. [[bug>2360]] |
| - | * Bug fix: Popup menus invoked from buttons were not working. | + | * SSH core and SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.84]]. \\ It brings the following changes: |
| + | * Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] | ||
| + | * Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] | ||
| + | * Bug fix: spurious //"Network error: Socket is not connected"// when authenticating to some HTTP proxies. [[pbug>http-proxy-auth-wsaenotconn]] | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.5.7. | ||
| + | * XML parser upgraded to Expat 2.8.1. | ||
| + | * Restored faster C TLS/SSL AES implementation. | ||
| + | ··* Configurable warning when opening large file in an internal editor. [[bug>2437]] | ||
| + | · * Informing that when preserving directory timestamps is enabled, using multiple connections for transfer is not possible. [[bug>2439]] | ||
| + | * Warning when pasting a session URL with unsafe settings. | ||
| + | * When opening session in PuTTY to a host for which WinSCP has multiple host keys cached, using the last key or the key that PuTTY has cached. [[bug>2440]] | ||
| + | * Always (re)registering drag&drop shell extension during installation, even when the extension is not replaced. | ||
| + | * Allowed Console interface tool to have ''.exe'' extension to avoid false positive detections by some antiviruses. [[bug>2434]] | ||
| + | * Using //"username"// and //"hostname"// as one word. | ||
| + | * Reading all system settings from 64-bit registry. | ||
| + | * Allow assigning ''null'' to ''Session.SessionLogPath''. [[bug>2438]] | ||
| + | * Avoiding using ''SSH_FXF_EXCL'' together with ''SSH_FXF_TRUNC'' SFTP file opening flags. [[bug>2444]] | ||
| + | * Optimized file system monitoring when looking for dummy directory during drag&drop downloads. [[bug>2445]] | ||
| + | * Change: Not allowing WebDAV redirects to other hosts by default. [[bug>2447]] | ||
| + | * Change: Not allowing WebDAV redirects to an unencrypted URL by default. [[bug>2448]] | ||
| + | * Updated to JCL library 2.9 commit c669fd12. | ||
| + | * Bug fix: Failure when trying to connect via HTTP proxy to FTP host with excessively long login details. [[bug>2435]] | ||
| + | * Bug fix: Buffer overflow in Console interface tool. [[bug>2436]] | ||
| + | * Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] | ||
| + | * Bug fix: Message boxes from secondary windows (like the internal editor) caused application to move to the background when when the main window was minimized. [[bug>2443]] | ||
| + | * Bug fix: Heap over-read via crafted encrypted filename. [[bug>2449]] | ||
| + | * Bug fix: Slashes in filenames can cause path traversal when invalid filename characters replacement is disabled. [[bug>2450]] | ||
| - | ===== [[4.0.1]] 4.0.1 beta ===== | + | ===== [[6.6.1]] 6.6.1 beta ((2026-04-01)) ===== |
| - | === 2007-05-28 === | + | |
| - | ··* FTP core upgraded to [[http://filezilla-project.org/|FileZilla 2.2.32]]. The upgrade solves some vulnerabilities. | + | |
| - | * When //Session// sheet is automatically selected on Login dialog (creation of new session, etc.), the //Host name// box is focused. | + | |
| - | * Username of the main session is reused for background transfers. | + | |
| - | * Different set of keepalive settings is used for FTP. FTP now has keepalives enabled by default. | + | |
| - | * For convenience, file mask "*." matches files without an extension (even if the name does not include the dot at all). | + | |
| - | * When window is minimized during transfer that is part of synchronization, it stays minimized till the end of synchronization. | + | |
| - | * After failure to open session requested from command line, login window is not shown. | + | |
| - | * Command //Open in PuTTY// uses tunnel for current session. | + | |
| - | * Global configuration that can be set on login dialog (user interface style, logging) is saved when session it saved. | + | |
| - | * ''Alt+F6'' now edits the link (if applicable). | + | |
| - | * Bug fix: Checksum calculation with SFTP protocol was not working at all. | + | |
| - | * Bug fix: For remote directories with names like "C:", the icons of local drives were used. | + | |
| - | * Bug fix: Proxy setting were ignored when setting up SSH tunnel. | + | |
| - | * Bug fix: Password for proxy was ignored with FTP. | + | |
| - | * Bug fix: SFTP uploads occasionally hanged. | + | |
| - | * Bug fix: Prompts (such as password prompts) for background transfers froze the main window. | + | |
| - | * Bug fix: It was not possible to change path by //Browse// button (such as path to a log file). | + | |
| - | * Bug fix: //Yes to All// on overwrite confirmation box was not working (FTP only). | + | |
| - | * Bug fix: For automatic transfers (uploads from editor, synchronization), the transfer was incorrectly automatically "resumed" when source file was larger than destination one, leaving content of file corrupted (FTP only). The issue may also make uploads from editor impossible in case server does not support (text file) transfer resuming. | + | |
| - | * Bug fix: Local files excluded from transfer (upload) were indefinitely locked by WinSCP. | + | |
| - | * Bug fix: Script failed once it needed to ask for password (with SFTP and SCP only). | + | |
| - | * Bug fix: //Open session in PUTTY// did not use stored password. | + | |
| - | * Bug fix: When switching back to WinSCP internal editor from another application, the main WinSCP window was focused instead. | + | |
| - | * Bug fix: When synchronization occurred while the //Keep remote directory up to date// dialog was minimized, it was not possible to restore it. | + | |
| - | ===== [[4.0]] 4.0 beta ===== | + | ··* Support for OpenSSH ssh-agent. [[bug>1682]] |
| - | === 2007-04-07 === | + | * Optionally connecting all workspace/folder sessions immediately. [[bug>1026]] |
| + | · * Preserving panel scroll position after rename. [[bug>2425]] | ||
| + | * ''Ctrl+C'' works in list views on 'Server and protocol information' dialog. | ||
| + | * Preventing moving or copying a file or folder over ancestor folder with the same name. [[bug>2427]] | ||
| + | * WebDAV/HTTP core upgraded to neon 0.37.1. | ||
| + | * XML parser upgraded to Expat 2.7.5. | ||
| + | ··* Bug fix: Some menus were not working on displays to the left or above the primary display. [[bug>2423]] | ||
| + | * Bug fix: Mouse wheel downwards scrolling did not work on toolbar drop down lists. | ||
| + | * Bug fix: Once any control of permissions popup box was focused the popup no longer closed when user clicked outside of it. | ||
| + | * Bug fix: Failure when closing Transfer settings dialog with //X// button while a permissions popup box control is focused. [[bug>2420]] | ||
| + | * Bug fix: Failure when switching to a session that is being reconnected. | ||
| + | * Bug fix: Failure when the first bit of an SFTP response is set. [[bug>2422]] | ||
| + | * Bug fix: Copying to clipboard with ''Ctrl+C'' from 'Server and protocol information' was broken. | ||
| + | * Bug fix: Protocol additional information scrolling was broken. | ||
| + | * Bug fix: Master password dialog was missing //Help// button. | ||
| + | * Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] | ||
| + | * Bug fix: Wrapped settings values from Raw Site Settings dialog were not preserved. | ||
| + | * Bug fix: Some files modified by local custom command in SCP session fail to upload back. [[bug>2428]] | ||
| + | * Bug fix: Whole //Key exchange// page was incorrectly hidden when //"Handles SSH key re-exchange badly"// bug was enabled. | ||
| + | * Bug fix: Some message boxes leak GDI handle. [[bug>2430]] | ||
| + | * Bug fix: Login dialog leaks GDI handles. [[bug>2431]] | ||
| - | ··* FTP support (based on [[http://filezilla-project.org/|FileZilla project]]). | + | ===== [[6.6]] 6.6 beta ((2026-02-02)) ===== |
| - | * WinSCP can itself setup SSH tunnel to allow indirect connections through proxy SSH host. | + | |
| - | * WinSCP executable is now named ''WinSCP.exe'' instead of ''WinSCP3.exe''. The same change applies to default installation path and //Start// menu group (for upgrades, existing ''WinSCP3'' path is preserved). | + | * Synchronizing two local directories. [[bug>2020]] |
| - | * Added simple "typical installation" option to setup that requires no further interaction from the user (apart from interface selection for fresh installs). | + | * Compiler upgraded to Clang/bcc32c. [[bug>618]] |
| - | * Optional minimization to taskbar notification area (system tray). | + | * Inactive sessions can be automatically reconnected. [[bug>2232]] |
| - | * When executed as standalone (not installed) for the very first time, an INI file is used by default, if user has write permissions to directory, where WinSCP is executed from. | + | * Added dark theme support to: [[bug>1696]] |
| - | * Taskbar balloons optionally used for notifications when appropriate: | + | ····* Login dialog. [[bug>2345]] |
| - | ···* When inactive session is disconnected. | + | * Transfer Options dialog. |
| - | ···* When background transfer queue is emptied (except for active session, when queue list is visible). | + | ····* Message boxes. |
| - | * When user interaction is required, while WinSCP is minimized. | + | ····* Queue column headers. [[bug>2356]] |
| - | ···* When new release is detected. | + | * Progress window. |
| - | * File checksum can be calculated from Properties dialog (providing the server supports the functionality). | + | ····* Authentication Progress window. [[bug>2358]] |
| - | * SFTP uploads optimized. | + | * Bug fix: Scrollbar colors did not always reflect the color theme |
| - | * New option for handling of remote file timestamps: //Preserve remote timestamp//. | + | ··* Using modern directory selection dialog that scales correctly and allows creating new directory. [[bug>2373]] [[bug>2389]] |
| - | * New scripting option ''option batch continue''. When set, WinSCP ignores and skips all errors. | + | * Optimized GUI when working with large subdirectory selection. [[bug>2396]] |
| - | * New scripting option ''option echo'' to enable echoing of commands being executed. | + | * Change: Default to UTF-8 encoding in internal editor. [[bug>2397]] |
| - | * New command to execute the last ad hoc custom command. | + | * New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. |
| - | * Tabs on Login dialog that have no usable option for current context (e.g. protocol) are hidden. | + | * TLS/SSL core upgraded to OpenSSL 3.5.5. |
| - | * "Host hasn’t answered for X seconds" message disappears itself once the response finally arrives also in scripting. | + | * WebDAV/HTTP core upgraded to neon 0.36.0. |
| - | * File edited in an internal editor can be reloaded (refreshed). | + | · * XML parser upgraded to Expat 2.7.4. |
| - | * Support for SSPI authentication. | + | * Installer upgraded to Inno Setup 6.7.0 with dark mode support enabled. |
| - | * Support for Kerberos ticket forwarding. | + | * Increased WinSCP memory limit to 4 GB. [[bug>2412]] |
| - | * Configuration can be exported to an INI file. | + | * Defined and implemented interface for the .NET library. By @mjkent. [[bug>856]] |
| - | * New command //Duplicate session//. | + | ·* Optimized TLS/SSL AES implementation. |
| - | * Mirror mode for synchronization, where files are updated on any timestamp difference (i.e. even newer files are updated). | + | ·* Restoring ability to restart Explorer to allow upgrade of drag&drop shell extension, when installing for current user, as after-restart replacement is not possible without Administrator privileges. [[bug>2381]] |
| - | * Custom commands history stores also the command options. | + | ·* MSI toolset updated to WiX 5. |
| - | * Preview changes for synchronization is enabled by default. | + | * Commands to copy paths to the clipboard on the Synchronization checklist window. |
| - | * Quick preset buttons for Windows and Unix systems on //Environment// tab of Login dialog (visible when advanced options are turned off only). | + | * Cryptography optimization. |
| - | * It is no longer required to specify username of login dialog. User is prompted for username once required (and only if required). | + | * Support long AWS/S3 session tokens. [[bug>2403]] |
| - | * Information shown on status bar were reduced. | + | * Prevent hang when new device is attached or removed while some mapped network drive is not available. [[bug>2382]] |
| - | * Environment variables can be used in most configurable paths (like path to random seed file, log file, configuration INI file, PuTTY executable, folder for temporary files, private key file, etc.). The syntax is ''%NAME%''. Part of U3 support. | + | * Copy and paste improvements: |
| - | * Script aborts eventually after receiving no answer for prompt (like password prompt), when running in batch mode. | + | ····* Consistently renaming local files dropped or pasted back to their source directory to avoid collisions. |
| - | * Whole authentication prompt is shown, even if it spans multiple lines. | + | ····* Bug fix: When copying local files to clipboard from system context menu, "cut" state of previously cut files was not cleared. |
| - | * When ''Shift'' key is hold while //New session// or //Duplicate session// commands are selected, the session is opened in new instance (window) of WinSCP. | + | * Not redundantly verifying WebDAV or S3 certificate in Windows Certificate store if it is already marked as trusted in session settings. [[bug>2404]] |
| - | * Button //Load// on //Stored sessions tab// of Login dialog renamed to //Edit//. | + | · * Provide SNI when opening FTP data connection. [[bug>2410]] |
| - | * ''F1'' opens help for current tab on Login and Preferences dialogs. | + | * Optimized synchronization checklist sorting. |
| - | ·* What's this button on dialog caption (''?'') opens help directly. | + | * Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] |
| - | ·* Button //Help// replaced with //Close// on Login dialog. | + | * Convert unsupported SSH proxy to SSH tunnel when importing site from PuTTY. [[bug>2408]] |
| - | ·* Single log file is used for all connections of one session (background transfer connections, secondary shell connection, tunnel connection). | + | * FTP directory listing falls back to the other active/passive mode, consistently with file transfers. |
| - | ·* During silent uninstall, user is not prompted for cleanup of application data. | + | ··* Consistently calling command to open window with specific directory //Explore//, instead of sometimes //Browse//. |
| - | * Workaround for SSH servers based on cryptlib, which reports invalid files types in response to ''SSH_FXP_LSTAT'' request. | + | * Consistently referring to file last modification timestamp column as //Date modified//. |
| - | ·* Configuration of GSSAPI/SSPI authentication is exported to PuTTY sessions. | + | * With INI file provided on command-line, using the same INI file when starting a new instance. |
| - | ·* When changing configuration storage, also caches (change directory cache, accepted SSH host keys, accepted banners) are transferred to the new storage. | + | * Windows shell local file copy status window is centered on the main window. |
| - | * Context menu of permissions popup and input boxes has clipboard management commands. | + | * Made taskbar flashing configurable in GUI. [[bug>2411]] |
| - | * Menu item captions capitalized according to Windows standard. | + | * Control labels on transfer settings dialogs do not show keyboard accelerator cue, until ''Alt'' key is pressed. |
| - | * More internal error messages from PuTTY code are being localized. | + | * Not using drag images even with directory trees. [[bug>1274]] |
| - | * When saving the edited session under the same name, overwrite confirmation is not requested. | + | * Allow configuring checksum commands. [[bug>2394]] |
| - | ·* Shell options of //SCP tab// of login dialog redesigned. | + | * Updated to JCL library 2.8.1. |
| - | ·* Timestamps are saved in numerical format into an INI file for portability among systems with different date/time format. | + | * Updating jump list only when running with GUI. |
| - | ·* Status bar message about preset auto-selection can be clicked to reveal information about the preset. | + | * Made space on permissions box for longer translations. [[bug>2398]] |
| - | * Preset information dialog has //Configure// button that opens preset preferences. | + | * Opening //Default Apps// //Settings// page directly to open it in the foreground and avoid flashing //Control Panel// window. |
| - | * Detection of OpenSSH sftp-server is more strict, not to apply on other SFTP servers running under OpenSSH. | + | * Improving order in which Windows Narrator reads window controls. |
| - | * Pattern hint link for log file name added. | + | * All edit boxes with history consistently do not auto complete and show 16 entries in the drop down. |
| - | * For fatal errors (e.g. "lost connection"), original cause of the problem is kept as a top message, as opposite to regular errors, where contextual error message is on top. | + | * Removed obsolete //Preserve remote timestamp// session settings. |
| - | ··* Buttons //Login// and //Save// on Login dialog swapped. | + | * Bug fix: Local file with invalid characters replaced could not be explored from the Synchronization checklist window. |
| - | ··* When //Handles SSH-2 key re-exchange badly// bug is enabled, the //Key exchange// tab is hidden. | + | * Bug fix: Files modified by local custom command are not always uploaded to the correct remote directory. [[bug>2370]] |
| - | * Web page shortcuts in //Start// menu are now direct shortcuts instead of shortcuts to ''URL'' file. | + | ··* Bug fix: List of network drives in drive drop down and directory tree did not always match. |
| - | * New button //What's new// on information box about updates. | + | ··* Bug fix: Host key prompt did not have the default button. |
| - | * Bug fix: Failure when changing languages (particularly with "Data execution protection" enabled). | + | * Bug fix: When the local path specified on Open directory/Location profile dialog is not existing, when browsing for a new path, the trailing part of the nonexisting path was appended to the new path. |
| - | * Bug fix: Failure, when remote command had character ''%'' in its error output. | + | * Bug fix: Trying to enter an invalid link in local panel fails silently. |
| - | * Bug fix: //Close// button were default even, if path box on //Space available// tab of Server and protocol information dialog had focus. | + | * Bug fix: After FTP data connection fails to open further use of the session is broken. |
| - | ··* Bug fix: Remote home directory of session was set to current working directory, after switching sessions. | + | * Bug fix: Pasting cut files from the clipboard into a local panel copies them instead of moving them. [[bug>2400]] |
| - | * Bug fix: Local home directory were changing while switching sessions, even when changing of local panel state with sessions is disabled. | + | * Bug fix: Some edits did not save their value to history when submitting with ''Enter''. |
| - | * Bug fix: INI file specified by filename-only using ''/ini'' parameter was not looked for in current working directory. | + | * Bug fix: Too long edit history dropdown can overflow monitor bounds. [[bug>2432]] |
| - | * Bug fix: Ad hoc command executed from file panel context menu was executed for selected files, despite the menu being opened for not-selected file. | + | * Bug fix: Message box texts and some control labels are not visible to screen readers. [[bug>2413]] |
| - | * Bug fix: Infinite loop of error messages when connection was broken while timeout message was being shown. | + | * Bug fix: Failure when clicking tab close button while the session is already being closed. [[bug>2416]] |
| - | * Bug fix: Trailing delimiter text were occasionally left in remote command output. | + | |
| - | * Bug fix: Some authentication progress steps were not shown on authentication window for secondary shell sessions. | + | ===== [[6.5.7]] 6.5.7 (not released yet) ((2026-08-25)) ===== |
| - | * Bug fix: Inactive sessions were not kept alive. | + | |
| - | * Bug fix: Incorrect sizing of internal editor windows opened on non-primary monitor. | + | * Translations completed: Croatian, Finnish, Georgian, Italian and Serbian. |
| - | * Bug fix: Automatic retry after timeout was not working. | + | * TLS/SSL core upgraded to OpenSSL 3.3.7. |
| - | * Bug fix: Stored session may be lost when letter case was changed solely during rename. | + | * SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. SSH core upgraded to include some fixes. \\ It brings the following change: |
| - | * Bug fix: It was not possible to cancel text mode upload with SCP protocol. | + | ···* Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] |
| - | * Bug fix: Change directory cache may become corrupted when using INI file for configuration. | + | ···* Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] |
| - | * Bug fix: Drag&drop download was not working, if relative path was used for temporary folder. Part of U3 support. | + | ···* Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] |
| - | * Bug fix: After startup, button on taskbar was not "pressed", even if WinSCP login dialog had focus. | + | ···* Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] |
| - | * Bug fix: Failure when closing console window. | + | * Back-propagated fixes from 6.6.2 beta release: |
| - | * Bug fix: When moving files from remote directory tree, the tree was not updated after operation, leaving icon for no-longer-existing directory. | + | ···* Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] |
| - | * Bug fix: Octal display of file permissions was not filled if no permissions were set for a file. | + | ···* Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] |
| - | * Bug fix: Failure to change attributes of local files was not reported sometime. | + | ···* Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] |
| + | * Bug fix: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. CVE-2026-45447 fix from OpenSSL 3.4.6. | ||
| + | |||
| + | ===== [[6.5.6]] 6.5.6 ((2026-03-25)) ===== | ||
| + | |||
| + | * Translations completed: Macedonian, and updated: Lithuanian, and Russian. | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.3.6. | ||
| + | * Back-propagated improvements from 6.6–6.6.1 beta release: | ||
| + | ····* New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. | ||
| + | ···* XML parser upgraded to Expat 2.7.5. | ||
| + | ···* Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] | ||
| + | ···* Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] | ||
| + | |||
| + | ===== [[6.5.5]] 6.5.5 ((2025-11-19)) ===== | ||
| + | |||
| + | * Translation updated: Vietnamese. | ||
| + | * Bug fix: Pasting files using local directory tree context menu pastes them to the current directory, instead of the selected one. | ||
| + | * Bug fix: Failure when opening site imported from PuTTY with unsupported SSH proxy. [[bug>2407]] | ||
| + | * Bug fix: Incorrect hostname validation when connecting to S3 endpoint with certificate that does not cover root S3 hostname. [[bug>2409]] | ||
| + | |||
| + | ===== [[6.5.4]] 6.5.4 ((2025-10-16)) ===== | ||
| + | |||
| + | * Translations updated: Belarusian and Georgian. | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.3.5. | ||
| + | * XML parser upgraded to Expat 2.7.3. | ||
| + | * Added new ''ap-southeast-6'' AWS region. | ||
| + | * Bug fix: When restored after operation completed while minimized the window is disabled. [[bug>2393]] | ||
| + | * Bug fix: Command ''md5sums'' is incorrectly used to calculate MD5 checksum instead of ''md5sum''. [[bug>2392]] | ||
| + | * Bug fix: Incomplete FTP upload when the source stream/stdin reads less than requested. [[bug>2395]] | ||
| + | * Bug fix: ''Shift''-clicking //OK// button on Synchronization checklist window when synchronization in the background was not possible still closed the window. | ||
| + | * Bug fix: Failure after reloading file panel when number of files decreases. [[bug>2402]] | ||
| + | * Bug fix: Failure or silently missing headers when when S3 request headers were too long. | ||
| + | |||
| + | ===== [[6.5.3]] 6.5.3 ((2025-07-16)) ===== | ||
| + | |||
| + | * Translations updated: Belarusian, Brazilian Portuguese [[bug>2386]] and Slovenian. | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.3.4. | ||
| + | * Temporarily not updating drag&drop shell extension for minor changes when installing for current user. [[bug>2381]] | ||
| + | * Bug fix: Failure when reading empty certificate authority configuration. | ||
| + | * Bug fix: Failure when running Maximized. [[bug>2387]] | ||
| + | * Bug fix: Incorrect scaling of navigation tree on Login and Preferences dialogs. [[bug>2385]] | ||
| + | * Bug fix: Incorrect scaling of drag&drop shell extension status display on Preferences dialog. | ||
| + | |||
| + | ===== [[6.5.2]] 6.5.2 ((2025-06-18)) ===== | ||
| + | |||
| + | * Translation updated: Brazilian Portuguese and Polish. | ||
| + | * Added new ''ap-east-2'' AWS region. | ||
| + | * Bug fix: Some translations (notably Japanese) are not loaded. [[bug>2372]] | ||
| + | * Bug fix: Directory tree indentation is scaled incorrectly when starting on scaled display on system with scaled primary monitor. [[bug>2374]] | ||
| + | * Bug fix: Wrong icon size is used when starting on secondary monitor with different scaling than the primary one. | ||
| + | * Bug fix: Failure when proxy hostname resolution fails with SFTP/SCP protocols. [[bug>2376]] | ||
| + | * Bug fix: Avoid replacing ''%2F'' with a slash and ''%2E'' with a dot in special cases on upload to avoid path traversal. [[bug>2377]] | ||
| + | * Bug fix: Failure when canceling reconnection on authentication banner, when the connection was already closed by the server. [[bug>2379]] | ||
| + | * Bug fix: Local directories sometimes cannot be deleted. [[bug>2380]] | ||
| [[history_old|Older versions]] | [[history_old|Older versions]] | ||
| ~~NOTOC~~ | ~~NOTOC~~ | ||
| + | ~~ARCHIVE=history_old~~ | ||