NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #1544 most downloaded on npm
FTP client for Node.js, supports FTPS over TLS, IPv6, Async/Await, and Typescript.
Last release today
04 Oct 2026
Ships unpredictably
gaps range from 3 weeks to 1.8 years
Nearly every release is documented
notes for 11 of 11 stable releases
114 versions withdrawn
withdrawn after publishing
9 years old
125 releases · first in 2017
Fixed: Protect against excessive CPU use when detecting an MLSD directory listing or parsing a PASV response, fixes https://github.com/patrickjuchli/b
Fixed: Protect against excessive CPU use when parsing a directory listing, fixes GHSA-c475-qrg2-pj4r .
One column per quarter.
Changed: Timeout tracking during data transfers now only applies to the server, not a slow local source or destination.
Changed: Uploading from a local path now throws if the file changes while it's being read, instead of reporting the incomplete upload as successful.
TLS session of data connection not resumed" on Node.js with the CVE-2026-48934 fix (22.23.0+, 24.17.0+, 26.3.1+).
Fixed: Use and renew TLS 1.3 session tickets for data connections. (Thanks for testing, @dennisameling )
Breaking change : This library does not allow separate transfer hosts by default anymore. This provides security by default against FTP bounce attacks…
allowSeparateTransferHost: true when instantiating a Client. (Thanks, @Jvr2022)allowSeparateTransferHost: true when instantiating a Client. (Thanks, @Jvr2022)Fixed: Protect against unbounded control response, fixes GHSA-rpmf-866q-6p89 .
Changed: Introduced an upper bound for total bytes of directory listing, fixes GHSA-rp42-5vxx-qpwr .
Fixed: Improve control character rejection, fixes GHSA-6v7q-wjvx-w8wg .
Fixed: Reject control character injection attempts using paths. See GHSA-chqc-8p9q-pq6q .
Changed: Skip files with invalid name in downloadToDir.
Added: Add the option to prevent the use of separate transfer host IPs when using PASV.
Fixed: Memory leak described in #250 by @everhardt, @martijnimhoff
Fixed: Handle relative paths in Client.removeDir()
Fixed: Avoid deprecation error.
Fixed: Use existing code path to close control socket when replacing it.
Fixed: Don't trust FEAT response of servers regarding EPSV.
Breaking change: Library requires at least Node version 10.
Fixed: Log reason why transfer modes fail when testing.
Fixed: Only use MLSD after querying support for feature.
Fixed: Hostname doesn't match certificates altnames for data connection. (#166, #179, @alandoherty)
Improved: Continue trying transfer strategies even after unexpected errors.
Fixed: Allow directory names ending with space in client.list(). (#149, @inithink)
Fixed: Missing StringEncoding in export.
Added: Support for implicit FTPS. (#121, @sparebytes)
Fixed: Catch server closing connection without error.
Fixed: Allow 'undefined' to be passed to trackProgress. (#125, @FabianMeul)
Fixed: Try next available list command after any FTP error.
Fixed: Remove eager check for remoteAddress of a socket.
remoteAddress of a socket. (#106)Added: Directory listings are included in transfer progress tracking.
Fixed: Return to former working directory also after error when calling directory-related methods.
Changed: Current API uploadDir and downloadDir has been deprecated, use uploadFromDir and downloadToDir.
uploadDir and downloadDir has been deprecated, use uploadFromDir and downloadToDir.downloadToDir.Fixed regression at 4.3.0: File descriptor closed too early.
Fixed: When downloading to a local file and an error occurs, only remove it if no data has been downloaded so far.
Added: More explicit API uploadFrom, appendFrom and downloadTo. upload and download are still available but deprecated.
uploadFrom, appendFrom and downloadTo. upload and download are still available but deprecated.uploadFrom and downloadTo.downloadTo for more details.Fixed: Don't rely on MLSD types 'cdir' and 'pdir', consider names as well.
Added: Support uploading a local directory to any specific remote directory instead of just the working directory.
Added: Support symbolic links in MLSD listings.
Fixed: Make MLSD listing detection more general.
Fixed: Describe client as closed before first connection
This release contains the following breaking changes:
This release contains the following breaking changes:
permissions property of FileInfo is now undefined if no Unix permissions are present. This is the case if for example the FTP server does not actually run on Unix. Before, permissions would have been set to 000. If permissions are present there is a good chance that a command like SITE CHMOD will work for the current server.date of FileInfo, you might have to consider a new ISO format coming with MLSD listings, e.g. 2018-10-25T12:04:59.000Z. Better yet, use the parsed date directly with modifiedAt and only use date if it is undefined. Be aware that parsing dates reported by the LIST command is likely unreliable.Non-breaking changes:
modifiedAt of FileInfo may hold a parsed date if the FTP server supports the MLSD command. Note that the property date is not parsed but only a human-readable string coming directly from the original listing response.sendIgnoringError to send an FTP command and ignoring a resulting FTP error. Using the boolean flag as the second argument of send has been deprecated.OPTS UTF8 ON when accessing a server.Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
No changes, republishing because of bug on npmjs.com.
No changes, republishing because of bug on npmjs.com.
Fixed: Fall back to LIST command if LIST -a is not supported.
LIST command if LIST -a is not supported. (#91)Fixed: Support non-standard response to EPSV by IBM i or z/OS servers.
Added: Use client.append() to append to an existing file on the FTP server.
client.append() to append to an existing file on the FTP server. (#83)Fixed: Use ESLint instead of TSLint.
Added: Users can access internal transfer modes to force a specific one.
Added: Make parseList public API. (#75, @xnerhu)
Added: Client list method supports optional path argument. (#69, @ThatOdieGuy)
list method supports optional path argument. (#69, @ThatOdieGuy)Fixed: Reject failing connection for passive transfer with Error instance.
Fixed: Handle multline response message closing without message.
Fixed: Unix directory listing in some cases interpreted as DOS listing.
Fixed: Close the current control connection when connect creates a new one that is not an upgrade.
connect creates a new one that is not an upgrade.Added: access and connect can reopen a closed Client.
access and connect can reopen a closed Client.access can be called again after failed login. (#56)No changes, republishing to fix some issue on NPM.
No changes, republishing to fix some issue on NPM.
Your coding agent can read these notes before it upgrades. Set up the MCP server →