Differences
This shows you the differences between the selected revisions of the page.
| history 2006-05-07 | history 2026-09-11 (current) | ||
| Line 1: | Line 1: | ||
| ====== Recent Version History ====== | ====== Recent Version History ====== | ||
| - | This is list of changes for each release of WinSCP. See also [[project_history|project history]]. | + | This is a full list of changes for each release of WinSCP. See also [[project_history|Project history]] and [[incompatible_changes|Incompatible changes between versions]]. |
| - | ===== Not Released Yet ===== | + | ===== [[6.8]] 6.8 (not released yet) ((2026-08-22)) ===== |
| - | === 2006-05-07 === | + | |
| - | * Notice is displayed for period of time on status bar on various events, including: | + | * Word wrapping in the internal editor can be toggled from toolbar menu. [[bug>2451]] |
| - | * Automatic selection of transfer setting preset. | + | |
| - | * Turning on/off of synchronised browsing. | + | |
| - | * New version release. | + | |
| - | * Synchronization checklist can be sorted by any column. | + | |
| - | * When downloading, up to date remote file modification time is used, instead of cached time shown in file panel. | + | |
| - | * File masks can select files also by their size. | + | |
| - | * Automatic refresh of remote directory after an operation can be disabled (also by keyboard shortcut ''Ctrl+Alt+R''). | + | |
| - | * Stored session can be renamed. | + | |
| - | * Synchronized browsing state is now part of session state. | + | |
| - | * Options dialogs for uploads, downloads, synchronization and //Keep remote directory up to date// invoked from command-line can be skipped using ''/defaults'' switch. | + | |
| - | * Transfer settings presets drop down menu improved to show information about the preset being selected. | + | |
| - | * Parameters ''/script'' and ''/command'' can be used without ''/console'' to run the script without creating a console window (works for ''.EXE'' only). | + | |
| - | * Overwrite configuration message offers possibility to transfer file under different name (SFTP-only). | + | |
| - | * Turning off the advanced options on Login dialog hides also some advanced controls on tabs that are otherwise visible. | + | |
| - | * //Edit// is not a default action for double-click. | + | |
| - | * When new version release is notified, the message indicates if it is beta version. | + | |
| - | * Exclude file mask in example transfer setting preset //Exclude temporaries// expanded with ''*~; #*; .#*''. | + | |
| - | * Error "EAccessViolation" is now replaced with more meaningful "Invalid access to memory" also in scripting. | + | |
| - | * Mere change from //Exclude mask// to //Include mask// is not shown in transfer setting overview unless the mask itself is specified too. | + | |
| - | * Main window no longed flashes when Preferences dialog is closed. | + | |
| - | * Location profiles are renamed inline now. | + | |
| - | * Confirmation of file recycling is configurable independently of file deleting. | + | |
| - | * Reading of remote directory can be cancelled by ''Esc'' key. | + | |
| - | * During authentication, usage of stored password is indicated. | + | |
| - | * ''Shift+Up/Down'' selects files. | + | |
| - | * Button //Cancel// is not disabled on message dialogs, when //Never ask me again// checkbox is checked. | + | |
| - | * Bug fix: Menus were always shown on primary monitor in multi-monitor environment. | + | |
| - | * Bug fix: WinSCP was not reflecting system-wide disabling of menu animations. | + | |
| - | · * Bug fix: Menus were not animated on Windows XP. | + | |
| - | * Bug fix: Failure when connecting thru proxy. | + | |
| - | * Bug fix: Major CPU consumption during prompt for password/passphrase. | + | |
| - | * Bug fix: It was not possible to edit remote files with name containing characters not allowed on Windows. | + | |
| - | * Bug fix: Timestamp synchronisation was not working properly for remote directory synchronisation. | + | |
| - | * Bug fix: Group control caption was truncated on some XP themes. | + | |
| - | * Bug fix: Button //Browse// on download options dialog was not preserving trailing backslash and operation mask. | + | |
| - | * Bug fix: Assertion in ''DirView.pas''. | + | |
| - | * Bug fix: Incorrect decoding of SFTP extension ''version''. | + | |
| - | * Bug fix: Command ''open'' in scripting failed if password was specified in its parameter. | + | |
| - | * Bug fix: Failure when last access time of file being uploaded could not be retrieved (typical for uploads from CD). | + | |
| - | * Bug fix: Incorrect validation of file masks separated by comma. | + | |
| - | * Bug fix: Before updates information is shown, query is sent to the server, if cached information were retrieved by another version of WinSCP. | + | |
| - | * Bug fix: Transfer option //New and updated file(s) only// was not being saved. | + | |
| - | * Bug fix: Command line switches ''/synchronize'' and ''/keepuptodate'' were not documented in syntax overview shown by ''/help'' switch. | + | |
| - | * Bug fix: When //Never ask me again// was checked on query for synchronization before starting //Keep remote directory up to date//, the synchronization was not performed. | + | |
| - | ===== 3.8 beta ===== | + | ===== [[6.6.4]] 6.6.4 (not released yet) ((2026-09-11)) ===== |
| - | === 2005-12-20 === | + | |
| + | ··* Increased length limit of proxy host name for updates preferences. [[bug>2456]] | ||
| + | · * Optionally default to keeping Login dialog open after opening session in PuTTY. [[bug>2459]] | ||
| + | * Improving placement of widows, particularly those opened, while the main window is not visible (notably during command-line operations). | ||
| + | * Bug fix: When selecting a site to perform a command-line operation with, it was possible to select a workspace or a folder, resulting in unexpected behaviour or failure. [[bug>2457]] | ||
| + | * Bug fix: After opening session in PuTTY, WinSCP process is never closed. [[bug>2458]] | ||
| + | * Bug fix: Invalid language code for Serbian was used for Microsoft Store package. [[bug>2460]] | ||
| - | ··* Synchronization enhanced: | + | ===== [[6.6.3]] 6.6.3 RC ((2026-09-03)) ===== |
| - | ····* When option //Preview changes// is turned on, checklist of synchronization actions is displayed, giving user option to review and confirm them all at once. | + | |
| - | * Option //Preview changes// works for timestamp synchronization too. | + | |
| - | ····* When list of directories watched by function //Keep Remote Directory Up To Date// is changed, new count is shown on log view. | + | |
| - | * Synchronization delay for function //Keep Remote Directory Up To Date// is configurable (only directly in configuration files). | + | |
| - | * Bug fix: When list of directories watched by function //Keep Remote Directory Up To Date// was changed, some of the subdirectories stopped being watched. | + | |
| - | * Bug fix: Option //Same size only// for timestamp synchronization was not working. | + | |
| - | * Bug fix: Newly added subdirectories were not watched for changes, when keeping remote directory up to date from script. | + | |
| - | * The connection can be automatically re-established when lost during file transfer (SFTP-only). | + | |
| - | * When the main session is reconnected the background transfer queue is now preserved. | + | |
| - | * The Server/Protocol Information dialog remade. It now also shows space available for current directory. | + | |
| - | * Color can be associated with session. It is used as background color for file panels. | + | |
| - | * Authentication window introduced. It combines progress display with authentication prompts. | + | |
| - | * Initial permissions can be set when creating new remote directory. | + | |
| - | * File panel can be sorted by extension by clicking on dedicated part of //Name/Ext// column title. | + | |
| - | * Permission errors when setting attributes (permissions and timestamp) of remote file can be suppressed using new transfer option //Ignore permissions errors// (SFTP-only). | + | |
| - | * Commands //Edit New File// and //Create Directory// moved to //New > File// and //New > Directory//. Command //Add/Edit Link// split into //Edit Link// and //New > Link//. Submenu //New// is also accessible from panel's context menu. | + | |
| - | * New panel option for Norton Commander-like interface: //Full row select// (turned on by default). Can be turned off to make panel's context menu more accessible. | + | |
| - | * New toolbar with custom commands. | + | |
| - | * New toolbar for Norton Commander-like interface with buttons //Upload// and //Download//, useful when you want to transfer file without having the source panel active. | + | |
| - | * New command (switch) for queue //Disconnect Once Empty// closes the session, if it's idle, when the last scheduled background transfer is finished. | + | |
| - | * System administrators can enforce display of authentication banners. | + | |
| - | * System administrators can restrict connection to servers without having their host keys accepted in advance. | + | |
| - | * Context menu of console output display includes command to resize the console window to fit the command output. | + | |
| - | * If the SFTP server does not provide file permissions/owner/group in directory listing, WinSCP requests them explicitly before showing Properties dialog. | + | |
| - | * Pressing button //OK// on fatal error message box for the initial session re-opens the Login dialog. | + | |
| - | * Only the last ''@'' in connection string is considered as username/hostname separator, making it possible to easier type username and/or password containing ''@'' from command-line. | + | |
| - | * "Edit" commands now open all selected files, not only focused one, if editing of multiple files is allowed. | + | |
| - | * Edited remote file can be uploaded, even if the session was reconnected meanwhile. | + | |
| - | * Transfer setting dialog has option //Do not show this dialog box again//, when transfer is invoked using drag&drop to disable future drag&drop transfer confirmation. | + | |
| - | * Optional "Office 2003" theme and few minor changes to toolbars. | + | |
| - | * Size of the console window is preserved. | + | |
| - | * When changing file properties, ''chgrp'' and ''chown'' are called before ''chmod'', because they change file permissions (SCP-only). | + | |
| - | * If the session is closed due to option //Disconnect when operation finishes//, associated background transfers are terminated immediately, not only after the user acknowledges the closure. | + | |
| - | * It is now possible to edit two files with the same path/name located on different servers. | + | |
| - | * Logging to file can be enabled using new ''/log'' command-line option. | + | |
| - | * Log file name can contain following patterns: ''&Y'' (year), ''&M'' (month), ''&D'' (day), ''&T'' (time), ''&H'' (hostname), ''&S'' (session name). | + | |
| - | * Improved cleaning of directory change cache on symbolic link deletion. | + | |
| - | * SFTP extension "versions", specifying list of supported protocol versions, is decoded and logged. | + | |
| - | * SFTP extension "supported" is ignored, when extension "supported2" is also sent by the server. | + | |
| - | * Custom transfer settings dialog disables settings unusable in current context (synchronization mode, server capabilities, etc.). | + | |
| - | * Transfer setting preset info tip does not show settings unusable in current context (server capabilities, etc.). | + | |
| - | * Setup does not overwrite update period, if updates were already enabled. | + | |
| - | * Transfer setting options "Permissions" and "Preserve read-only" are disabled when the server does not support permissions. | + | |
| - | * On Windows XP, native column sorting icons are used. | + | |
| - | * Licence of PuTTY updated. | + | |
| - | * Command //Copy URL to Clipboard// now URL-encodes some characters (space particularly). | + | |
| - | * WinSCP can handle URL with URL-encoded characters in session name. | + | |
| - | * URL handler registered by WinSCP now encloses the URL into quotes to allow handling of URL's with space. | + | |
| - | * WinSCP can load plain text password from configuration (new attribute ''PasswordPlain''). If possible, it automatically converts the password to encrypted form. | + | |
| - | * File mask ''*.*'' is treated exceptionally, matching all files, even those without dot. | + | |
| - | * Internal editor window is activated before associated message box pops up (e.g. save confirmation). | + | |
| - | * //Preferences// command added to context menu of internal editor. | + | |
| - | * Navigation tree on login and preferences dialogs widened to allow longer translations. | + | |
| - | * When sorting files in file panel, filename is always secondary criteria. | + | |
| - | * INI file name on Properties dialog changes with name of executable. | + | |
| - | * Option ''/script='' without value is ignored. | + | |
| - | * //Server response timeout// can be set up to 6000 seconds. | + | |
| - | * Popup hints close on mouse click. | + | |
| - | * Bug fix: Fixed resolving symbolic links in sub-directories. | + | |
| - | * Bug fix: After directory refresh, WinSCP sometime incorrectly behaved as if the user were dragging the selected file. | + | |
| - | * Bug fix: SCP fallback for SSH-1 was not working. | + | |
| - | * Bug fix: Uploads of files into previously non-existing directory could not be resumed (SFTP-only). | + | |
| - | * Bug fix: Selection could not be restored after changing file properties. | + | |
| - | * Bug fix: WinSCP hung on start-up occasionally (for example when the main window was closed maximised on different screen resolution the last time). | + | |
| - | * Bug fix: Failure when changing file properties on SFTP server supporting UTF-8. | + | |
| - | * Bug fix: Incorrectly formatted message "Unknown principal". | + | |
| - | * Bug fix: Hint on status bar for transfer setting preset selector incorrectly showed preset configuration. | + | |
| - | * Bug fix: Custom transfer settings dialog invoked from context menu on synchronization dialog did incorrectly allowed changing all settings, even when time-stamp-only synchronization was selected. | + | |
| - | * Bug fix: When the SFTP server does not support permissions, random permissions were used for the files. | + | |
| - | * Bug fix: Crash when re-key occurred on idle background session and the host key was not cached. | + | |
| - | * Bug fix: Failure when downloading file from different directory than the current one (SCP only) | + | |
| - | * Bug fix: Username was stored incorrectly when exporting session to PuTTY. | + | |
| - | * Bug fix: On the first start-up on fresh installation, default editor settings were not preset. | + | |
| - | * Bug fix: When output of the console is was redirected to file, list of transferred files contained only the last file. | + | |
| - | * Bug fix: Editors list was lost when changing configuration storage. | + | |
| - | * Bug fix: //Mouse only// option of //Explorer style selection// was not preserved. | + | |
| - | * Bug fix: When password storing is restricted, warning that password is being stored is no longer shown. | + | |
| - | ===== 3.7.6 ===== | + | ··* Translations completed: Belarusian, Brazilian Portuguese, Catalan, Croatian, Czech, Danish, Dutch, Finnish, French, German, Hungarian, Italian, Japanese, Korean, Lithuanian, Macedonian, Polish, Portuguese, Romanian, Russian, Serbian, Simplified Chinese, Slovak, Slovenian, Spanish, Swedish, Tamil, Traditional Chinese and Turkish. |
| - | === 2005-08-15 === | + | ·* Some parts of GUI (panel headers, scrollbars, buttons, checkboxes) show dark in dark theme even when system-wide app theme is light. |
| - | * Editing files enhanced: | + | ·* SSH core and private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. \\ It brings the following change: |
| - | ···* There can be several external editors configured. | + | * Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] |
| - | ···* Appropriate editor for particular file can be selected automatically by file mask (i.e. file extension, directory, etc.). | + | * Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] |
| - | ···* Command //File(s) > Edit (alternative)// replaced with sub menu listing all available editors. | + | * Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] |
| - | * Command //File(s) > Edit new// has now keyboard shortcut originally used by //File(s) > Edit (alternative)//. | + | * Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] |
| - | * File can be optionally opened in editor as response to double-click. | + | ·* Bundled SSH private key tools (PuTTYgen and Pageant) are 64-bit. |
| - | * Change to internal editor configuration is immediately applied to all already opened editor windows. | + | ·* On Windows 11, using system dark tab theme, that uses different shades for active and disabled/disconnected tabs. [[bug>2452]] |
| - | ···* Search options are shared among opened internal editors. | + | ·* TLS/SSL core upgraded to OpenSSL 3.5.8. |
| - | ···* Search dialogs have context help. | + | * XML parser upgraded to Expat 2.8.4. |
| - | ···* Bug fix: Application could not be closed as long as any internal editor was opened. | + | ·* Source code package build script supports 64-bit target. |
| - | ···* Bug fix: "Total replacements" message sometime incorrectly appeared, even when //Replace All// was not used. | + | * Installer upgraded to Inno Setup 6.7.3. |
| - | ···* Bug fix: Find results sometime appeared over the main window instead of over the editor window. | + | · * 64-bit build is identified in version information. |
| - | ···* Bug fix: Search dialogs were sometime incorrectly placed. | + | ·* Resolving version of pwsh installed with MSIX. |
| - | * Authentication banner, if any, is shown during authentication. | + | * Thirdparty information from the About dialog can be copied to the clipboard even when the browser control malfunctions. |
| - | * New functions for queue management: //Suspend//, //Resume//, //Suspend All// and //Resume All//. | + | ·* Bug fix: No error is shown when connection fails. |
| - | * Unix-style approach to Daylight saving time (client does adjustment) is made default. This can affect interpretation of timestamps of your files. Use function //[[task_synchronize_full|Synchronize]]// with option //[[ui_synchronize#synchronize_options|Synchronize timestamps only, not files]]// to resolve it. | + | * Bug fix: ''x-name'' URL parameter was incorrectly decoded. |
| - | * Button //Calculate// on Properties dialog calculates also total number of files/directories/symlinks. The button newly also does not show up, when all selected directories are actually symlinks. | + | * Bug fix: Incorrect number validation. |
| - | · * Several changes to synchronization: | + | * Bug fix: Some controls (notably list view headers) do not correctly apply dark mode in 64-bit build. [[bug>2453]] |
| - | * Added new option //Selected files only// for functions //Synchronize// and //Keep Remote Directory Up To Date//. It limits the synchronization to files selected in either panel only. | + | * Bug fix: 64-bit build did not identify its system to be 64-bit, what among other prevented it from identifying 64-bit COM registrations. |
| - | * Removed option //No confirmations// for functions //Synchronize// and //Keep Remote Directory Up To Date//. Confirmations are now disabled always. | + | * Bug fix: Some strings use incorrect translation in 64-bit version. [[bug>2455]] |
| - | ···* Directory number limit for function //Keep remote directory up to date// can be overruled. | + | |
| - | ···* Event log is shown for function //Keep remote directory up to date//. | + | ===== [[6.6.2]] 6.6.2 RC ((2026-06-17)) ===== |
| - | ···* When synchronizing timestamps, only same-sized files can be affected optionally. | + | |
| - | ···* For //Synchronize timestamps only, not files// mode the only item of transfer settings that can be set (and that is displayed) is exclusion/inclusion mask. | + | * Experimental 64-bit version of WinSCP. [[bug>618]] |
| - | ···* //Keep remote directory up to date// can be interrupted by ''ESC''. | + | * Optionally not showing error message when connection is lost while idle. [[bug>2360]] |
| - | * Bug fix: Failure when synchronization before //Keep remote directory up to date// was interrupted. | + | * SSH core and SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.84]]. \\ It brings the following changes: |
| - | ···* Bug fix: When time-stamp synchronization was configured as default synchronization action, it was incorrectly inherited by //Keep remote directory up to date//. | + | * Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] |
| - | * Several changes to scripting: | + | * Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] |
| - | * New scripting option ''option batch abort''. When set, WinSCP will abort the script as soon as any of the commands fail. Values ''on'' and ''off'' are still available with unchanged behaviour. | + | * Bug fix: spurious //"Network error: Socket is not connected"// when authenticating to some HTTP proxies. [[pbug>http-proxy-auth-wsaenotconn]] |
| - | ···* New scripting options ''include'' and ''exclude'' to set include/exclude masks. Only one of the two can be set at a time. | + | * TLS/SSL core upgraded to OpenSSL 3.5.7. |
| - | ···* ''Ctrl+C'' during script file processing breaks whole script, not only current command. | + | ·* XML parser upgraded to Expat 2.8.1. |
| - | ···* During synchronization names of directories where change happened are displayed only. | + | * Restored faster C TLS/SSL AES implementation. |
| - | ···* Bug fix: Script file loading errors were displayed in message box instead of console. | + | ·* Configurable warning when opening large file in an internal editor. [[bug>2437]] |
| - | ···* Bug fix: Scripting have not inherited configured synchronization settings. | + | ·* Informing that when preserving directory timestamps is enabled, using multiple connections for transfer is not possible. [[bug>2439]] |
| - | ···* Bug fix: Incorrect parameter syntax in help for scripting command ''open''. Thanks to Gottfried Haider. | + | ·* Warning when pasting a session URL with unsafe settings. |
| - | ···* Bug fix: Second consecutive ''put'' command from script file overwrites output of previous one. | + | * When opening session in PuTTY to a host for which WinSCP has multiple host keys cached, using the last key or the key that PuTTY has cached. [[bug>2440]] |
| - | * When overwritting of remote file fails, WinSCP can try to delete file and create new one (SFTP only). | + | ·* Always (re)registering drag&drop shell extension during installation, even when the extension is not replaced. |
| - | * New custom command option //Copy results to clipboard//. | + | * Allowed Console interface tool to have ''.exe'' extension to avoid false positive detections by some antiviruses. [[bug>2434]] |
| - | * Workaround for OpenSSH limit of 256 kB for size of SFTP packet. Consequence was occasional interruption of transfer with error "Connection has been unexpectedly closed. Server sent command exit status 11." | + | * Using //"username"// and //"hostname"// as one word. |
| - | * All new sessions can be automatically opened also in PuTTY. | + | * Reading all system settings from 64-bit registry. |
| - | * The Office XP-like look can be turned off from //Interface tab// of Preferences dialog. | + | * Allow assigning ''null'' to ''Session.SessionLogPath''. [[bug>2438]] |
| - | * WinSCP remembers what location profile folders were opened. | + | ·* Avoiding using ''SSH_FXF_EXCL'' together with ''SSH_FXF_TRUNC'' SFTP file opening flags. [[bug>2444]] |
| - | * New //Type// column for remote panel (hidden by default). | + | · * Optimized file system monitoring when looking for dummy directory during drag&drop downloads. [[bug>2445]] |
| - | * Default private key can be specified using ''/privatekey'' option. | + | ··* Change: Not allowing WebDAV redirects to other hosts by default. [[bug>2447]] |
| - | * User is notified when selected private key file does not contain private key in supported format or when the private key is for different SSH version than preferred one. | + | * Change: Not allowing WebDAV redirects to an unencrypted URL by default. [[bug>2448]] |
| - | * New file selection command //Restore Selection// which restores file selection before last file operation. | + | ·* Updated to JCL library 2.9 commit c669fd12. |
| - | * Characters not allowed in Windows file names are now replaced by ''%XX'' (where ''XX'' is hexadecimal representation of character ASCII code), instead of underscore (''_''). | + | ·* Bug fix: Failure when trying to connect via HTTP proxy to FTP host with excessively long login details. [[bug>2435]] |
| - | * Increased chance that files information on overwrite confirmation message are properly aligned (English version only). | + | ·* Bug fix: Buffer overflow in Console interface tool. [[bug>2436]] |
| - | * New optional file selection mode in Norton Commander interface, where mouse behaves as in Windows Explorer and keyboard behaves as in Norton Commander. | + | ·* Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] |
| - | * Files dropped on newly created desktop icons, associated with particular stored session, are uploaded. | + | * Bug fix: Message boxes from secondary windows (like the internal editor) caused application to move to the background when when the main window was minimized. [[bug>2443]] |
| - | * File mask ending with slash matches directories only. This is particularly useful for include mask to match any directories using mask ''*/''. | + | ·* Bug fix: Heap over-read via crafted encrypted filename. [[bug>2449]] |
| - | * When appending (including alternative resume), the target file is not deleted, when transfer is canceled by user. | + | * Bug fix: Slashes in filenames can cause path traversal when invalid filename characters replacement is disabled. [[bug>2450]] |
| - | * Custom command parameters are escaped for remote commands. For ''!?prompt[\]?default!'' pattern, escaping can be avoided using optional slash (''\''). | + | |
| - | * Added hint links to several dialogs. They open popup hint describing syntax of masks and custom command patterns. | + | ===== [[6.6.1]] 6.6.1 beta ((2026-04-01)) ===== |
| - | * About dialog redesigned. URL links can receive focus, to allow opening the URL using keyboard. Additional URL link can be associated with translation. | + | |
| - | * Confirmation of overwritting read-only files can be suppressed the same way as overwrite confirmation, i.e. by disabling confirmation for synchronization, background transfers or in script. | + | * Support for OpenSSH ssh-agent. [[bug>1682]] |
| - | * When saving location profile, existing profile can be overwritten (names of existing profiles are provided for selection in drop down menu), giving limited ability to edit profiles. | + | * Optionally connecting all workspace/folder sessions immediately. [[bug>1026]] |
| - | * When one of the directories of location profile does not exist anymore, the latter is opened, before error shows up. | + | * Preserving panel scroll position after rename. [[bug>2425]] |
| - | * Added new error messages as defined by SFTP-6. | + | * ''Ctrl+C'' works in list views on 'Server and protocol information' dialog. |
| - | * Maximal size of read block as requested by SFTP server using ''supported2'' extension is respected. | + | * Preventing moving or copying a file or folder over ancestor folder with the same name. [[bug>2427]] |
| - | * New option to lock placement of toolbars. | + | * WebDAV/HTTP core upgraded to neon 0.37.1. |
| - | * Added ''/command'' option to usage screen (''/help''). | + | * XML parser upgraded to Expat 2.7.5. |
| - | * //Cache directory changes// checkbox is disabled when //Cache visited remote directories// is unchecked and SCP-only mode is selected. | + | * Bug fix: Some menus were not working on displays to the left or above the primary display. [[bug>2423]] |
| - | * Empty proxy password is not "saved" to reduce session data size. | + | * Bug fix: Mouse wheel downwards scrolling did not work on toolbar drop down lists. |
| - | * When reloading directory content, file panel tries to preserve its position. | + | * Bug fix: Once any control of permissions popup box was focused the popup no longer closed when user clicked outside of it. |
| - | * When checking //Never ask me again// checkbox, all answer buttons are disabled except for the positive one, to avoid confusion. | + | * Bug fix: Failure when closing Transfer settings dialog with //X// button while a permissions popup box control is focused. [[bug>2420]] |
| - | * More informative error message when setting permissions of uploaded directory fails. | + | * Bug fix: Failure when switching to a session that is being reconnected. |
| - | * File masks can be separated also by comma (in addition to semicolon). | + | * Bug fix: Failure when the first bit of an SFTP response is set. [[bug>2422]] |
| - | * Dialog for entering deselection mask has //Deselect// title now. | + | * Bug fix: Copying to clipboard with ''Ctrl+C'' from 'Server and protocol information' was broken. |
| - | * It is now possible to specify both password and private key on Login dialog (server may require double authentication). | + | * Bug fix: Protocol additional information scrolling was broken. |
| - | * Confirmation is required before stored session is deleted. | + | * Bug fix: Master password dialog was missing //Help// button. |
| - | * Too long authentication prompts can be revealed also using keyboard. | + | * Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] |
| - | * Queue command //Delete// renamed to //Cancel// to avoid confusion with delete file command. | + | * Bug fix: Wrapped settings values from Raw Site Settings dialog were not preserved. |
| - | * Usage of ellipsis (...) and capital letters in menus revised. | + | * Bug fix: Some files modified by local custom command in SCP session fail to upload back. [[bug>2428]] |
| - | * Splitters have hints describing their specific functionality. | + | * Bug fix: Whole //Key exchange// page was incorrectly hidden when //"Handles SSH key re-exchange badly"// bug was enabled. |
| - | * Double clicking some of the splitters hide component they resize. | + | * Bug fix: Some message boxes leak GDI handle. [[bug>2430]] |
| - | * Commands toolbar has initially vertical layout when undocked. | + | * Bug fix: Login dialog leaks GDI handles. [[bug>2431]] |
| - | * When reading of local file during upload fails, more descriptive error message is shown and //Skip// button is not offered (SCP only). | + | |
| - | * When automatic popup of background transfer prompts is disabled, task bar button at least flashes when WinSCP is on background. | + | ===== [[6.6]] 6.6 beta ((2026-02-02)) ===== |
| - | * Obsolete temporary directories are no longer checked, when WinSCP is run for service task (such as registration for URL handling). | + | |
| - | ·* Bug fix: When using MS Virtual Desktop Manager, the main window of WinSCP was enlarged, when its virtual desktop was activated. Other associated issues are pending. | + | * Synchronizing two local directories. [[bug>2020]] |
| - | * Bug fix: Stored session name was not recognized in URL's containing path suffix. | + | * Compiler upgraded to Clang/bcc32c. [[bug>618]] |
| - | * Bug fix: When remote file was opened (not edited) in an external application that opens multiple files in window (process), WinSCP incorrectly suggested to enable support for this kind of //editors//. Now it suggests to configure the application as an external editor. | + | ··* Inactive sessions can be automatically reconnected. [[bug>2232]] |
| - | ·* Bug fix: Wrong default action was highlighted in remote file context menu when resolving of symbolic links is turned off or impossible. | + | * Added dark theme support to: [[bug>1696]] |
| - | ·* Bug fix: When directory was removed its cache was not, making it possible to enter no longer existing directory by typing its path manually. | + | * Login dialog. [[bug>2345]] |
| - | * Bug fix: SCP fallback was not working in 3.7.5. | + | * Transfer Options dialog. |
| - | * Bug fix: Include mask was not saved in configuration. | + | * Message boxes. |
| - | * Bug fix: Command //Open in PuTTY// was not working when current session was not opened from stored session. | + | * Queue column headers. [[bug>2356]] |
| - | * Bug fix: When there were too frequent changes to current local directory the panel content was never refreshed. | + | * Progress window. |
| - | * Bug fix: Failure when directory was reloaded while file was being renamed. | + | ····* Authentication Progress window. [[bug>2358]] |
| - | * Bug fix: Layout of some toolbars was not restored when using INI file as configuration storage. | + | * Bug fix: Scrollbar colors did not always reflect the color theme |
| - | * Bug fix: Occasional failure when opening Preferences dialog. | + | * Using modern directory selection dialog that scales correctly and allows creating new directory. [[bug>2373]] [[bug>2389]] |
| - | * Bug fix: Custom transfer settings dialog had some controls incorrectly disabled when invoked from Keep remote directory up to date dialog by double-clicking the transfer settings panel. | + | * Optimized GUI when working with large subdirectory selection. [[bug>2396]] |
| - | * Bug fix: Custom transfer settings dialog had incorrect help context. | + | * Change: Default to UTF-8 encoding in internal editor. [[bug>2397]] |
| - | * Bug fix: Incorrect files were selected when using ''Shift-click'' after reloading directory after using ''Left'' or ''Right'' keys to select first or last file. | + | * New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. |
| - | * Bug fix: Incorrect help context for message informing about autoselection of transfer settings preset. | + | * TLS/SSL core upgraded to OpenSSL 3.5.5. |
| - | * Bug fix: Inccorect behaviour after two consecutive clicks on //Execute// command of queue. | + | ··* WebDAV/HTTP core upgraded to neon 0.36.0. |
| - | * Bug fix: It was possible to enter invalid mask to transfer setting preset autoselection rule. | + | * XML parser upgraded to Expat 2.7.4. |
| - | * Bug fix: //Help// button on console window was incorrectly anchored. | + | * Installer upgraded to Inno Setup 6.7.0 with dark mode support enabled. |
| + | * Increased WinSCP memory limit to 4 GB. [[bug>2412]] | ||
| + | ··* Defined and implemented interface for the .NET library. By @mjkent. [[bug>856]] | ||
| + | ··* Optimized TLS/SSL AES implementation. | ||
| + | · * Restoring ability to restart Explorer to allow upgrade of drag&drop shell extension, when installing for current user, as after-restart replacement is not possible without Administrator privileges. [[bug>2381]] | ||
| + | * MSI toolset updated to WiX 5. | ||
| + | * Commands to copy paths to the clipboard on the Synchronization checklist window. | ||
| + | * Cryptography optimization. | ||
| + | * Support long AWS/S3 session tokens. [[bug>2403]] | ||
| + | * Prevent hang when new device is attached or removed while some mapped network drive is not available. [[bug>2382]] | ||
| + | * Copy and paste improvements: | ||
| + | * Consistently renaming local files dropped or pasted back to their source directory to avoid collisions. | ||
| + | ····* Bug fix: When copying local files to clipboard from system context menu, "cut" state of previously cut files was not cleared. | ||
| + | * Not redundantly verifying WebDAV or S3 certificate in Windows Certificate store if it is already marked as trusted in session settings. [[bug>2404]] | ||
| + | * Provide SNI when opening FTP data connection. [[bug>2410]] | ||
| + | * Optimized synchronization checklist sorting. | ||
| + | * Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] | ||
| + | * Convert unsupported SSH proxy to SSH tunnel when importing site from PuTTY. [[bug>2408]] | ||
| + | * FTP directory listing falls back to the other active/passive mode, consistently with file transfers. | ||
| + | * Consistently calling command to open window with specific directory //Explore//, instead of sometimes //Browse//. | ||
| + | ··* Consistently referring to file last modification timestamp column as //Date modified//. | ||
| + | ··* With INI file provided on command-line, using the same INI file when starting a new instance. | ||
| + | * Windows shell local file copy status window is centered on the main window. | ||
| + | * Made taskbar flashing configurable in GUI. [[bug>2411]] | ||
| + | ··* Control labels on transfer settings dialogs do not show keyboard accelerator cue, until ''Alt'' key is pressed. | ||
| + | * Not using drag images even with directory trees. [[bug>1274]] | ||
| + | * Allow configuring checksum commands. [[bug>2394]] | ||
| + | * Updated to JCL library 2.8.1. | ||
| + | * Updating jump list only when running with GUI. | ||
| + | * Made space on permissions box for longer translations. [[bug>2398]] | ||
| + | * Opening //Default Apps// //Settings// page directly to open it in the foreground and avoid flashing //Control Panel// window. | ||
| + | * Improving order in which Windows Narrator reads window controls. | ||
| + | * All edit boxes with history consistently do not auto complete and show 16 entries in the drop down. | ||
| + | * Removed obsolete //Preserve remote timestamp// session settings. | ||
| + | * Bug fix: Local file with invalid characters replaced could not be explored from the Synchronization checklist window. | ||
| + | * Bug fix: Files modified by local custom command are not always uploaded to the correct remote directory. [[bug>2370]] | ||
| + | * Bug fix: List of network drives in drive drop down and directory tree did not always match. | ||
| + | * Bug fix: Host key prompt did not have the default button. | ||
| + | * Bug fix: When the local path specified on Open directory/Location profile dialog is not existing, when browsing for a new path, the trailing part of the nonexisting path was appended to the new path. | ||
| + | ··* Bug fix: Trying to enter an invalid link in local panel fails silently. | ||
| + | * Bug fix: After FTP data connection fails to open further use of the session is broken. | ||
| + | ··* Bug fix: Pasting cut files from the clipboard into a local panel copies them instead of moving them. [[bug>2400]] | ||
| + | * Bug fix: Some edits did not save their value to history when submitting with ''Enter''. | ||
| + | * Bug fix: Too long edit history dropdown can overflow monitor bounds. [[bug>2432]] | ||
| + | * Bug fix: Message box texts and some control labels are not visible to screen readers. [[bug>2413]] | ||
| + | * Bug fix: Failure when clicking tab close button while the session is already being closed. [[bug>2416]] | ||
| + | |||
| + | ===== [[6.5.9]] 6.5.9 (not released yet) ((2026-09-10)) ===== | ||
| + | |||
| + | * Back-propagated fixes from 6.6.4 release: | ||
| + | * Bug fix: Invalid language code for Serbian was used for Microsoft Store package. [[bug>2460]] | ||
| + | |||
| + | ===== [[6.5.8]] 6.5.8 ((2026-09-10)) ===== | ||
| + | |||
| + | * This is Microsoft Store-only release that fixes packaging problem of 6.5.7. The actual binaries are still 6.5.7. | ||
| + | ···* Bug fix: Cannot install from Microsoft Store because of invalid 'sr' language. [[bug>2460]] | ||
| + | |||
| + | ===== [[6.5.7]] 6.5.7 ((2026-09-09)) ===== | ||
| + | |||
| + | * Translations completed: Croatian, Finnish, Georgian, Italian and Serbian, and updated: Slovenian. | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.3.7. | ||
| + | * SSH private key tools (PuTTYgen and Pageant) upgraded to [[&url(puttychanges)|PuTTY 0.85]]. SSH core upgraded to include some fixes. \\ It brings the following change: | ||
| + | ···* Security issue: fixed a remotely triggerable use-after-free in Pageant. [[pbug>pageant-deferred-decryption-uaf]] | ||
| + | * Security issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. [[pbug>etm-large-packet-overflow]] | ||
| + | * Security issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. [[pbug>argon2-parameter-checks]] | ||
| + | ···* Denial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. [[pbug>maxpkt-0-tight-loop]] | ||
| + | ···* Security issue: fixed a remotely triggerable double-free in RSA key exchange. [[pbug>rsakex-double-free]] | ||
| + | * Minor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. [[pbug>ecdsa-remotely-triggerable-assertion]] | ||
| + | * Back-propagated fixes from 6.6.2 beta release: | ||
| + | ····* Bug fix: Failure setting ''Session.DebugLogPath'' when running in impersonated context. [[bug>2441]] | ||
| + | * Bug fix: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. CVE-2026-45447 fix from OpenSSL 3.4.6. | ||
| + | |||
| + | ===== [[6.5.6]] 6.5.6 ((2026-03-25)) ===== | ||
| + | |||
| + | * Translations completed: Macedonian, and updated: Lithuanian, and Russian. | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.3.6. | ||
| + | * Back-propagated improvements from 6.6–6.6.1 beta release: | ||
| + | ····* New DigiCert EV code signing certificate valid until March 2029 is used for signing binaries. | ||
| + | * XML parser upgraded to Expat 2.7.5. | ||
| + | * Support for Beyond Compare 5 in Compare Files extension. [[bug>2417]] | ||
| + | ····* Bug fix: Checking if edited/opened file was modified externally didn't work for inactive sessions. [[bug>2426]] | ||
| + | |||
| + | ===== [[6.5.5]] 6.5.5 ((2025-11-19)) ===== | ||
| + | |||
| + | * Translation updated: Vietnamese. | ||
| + | * Bug fix: Pasting files using local directory tree context menu pastes them to the current directory, instead of the selected one. | ||
| + | * Bug fix: Failure when opening site imported from PuTTY with unsupported SSH proxy. [[bug>2407]] | ||
| + | * Bug fix: Incorrect hostname validation when connecting to S3 endpoint with certificate that does not cover root S3 hostname. [[bug>2409]] | ||
| + | |||
| + | ===== [[6.5.4]] 6.5.4 ((2025-10-16)) ===== | ||
| + | |||
| + | * Translations updated: Belarusian and Georgian. | ||
| + | * TLS/SSL core upgraded to OpenSSL 3.3.5. | ||
| + | * XML parser upgraded to Expat 2.7.3. | ||
| + | * Added new ''ap-southeast-6'' AWS region. | ||
| + | * Bug fix: When restored after operation completed while minimized the window is disabled. [[bug>2393]] | ||
| + | * Bug fix: Command ''md5sums'' is incorrectly used to calculate MD5 checksum instead of ''md5sum''. [[bug>2392]] | ||
| + | * Bug fix: Incomplete FTP upload when the source stream/stdin reads less than requested. [[bug>2395]] | ||
| + | * Bug fix: ''Shift''-clicking //OK// button on Synchronization checklist window when synchronization in the background was not possible still closed the window. | ||
| + | * Bug fix: Failure after reloading file panel when number of files decreases. [[bug>2402]] | ||
| + | * Bug fix: Failure or silently missing headers when when S3 request headers were too long. | ||
| [[history_old|Older versions]] | [[history_old|Older versions]] | ||
| ~~NOTOC~~ | ~~NOTOC~~ | ||
| + | ~~ARCHIVE=history_old~~ | ||