# \[ANN\] LibSSH.jl: a Julia wrapper for libssh

**URL:** <https://discourse.julialang.org/t/ann-libssh-jl-a-julia-wrapper-for-libssh/109766>\
**Category:** Package Announcements\
**Tags:** ssh\
**Created:** [February 5, 2024, 9:40pm UTC](https://discourse.julialang.org/t/ann-libssh-jl-a-julia-wrapper-for-libssh/109766 "2024-02-05T21:40:39Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![JamesNZ](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jamesnz/32/35361_2.png) [@JamesNZ](https://discourse.julialang.org/u/JamesNZ)\
**Post date:** [February 5, 2024, 9:40pm UTC](https://discourse.julialang.org/t/ann-libssh-jl-a-julia-wrapper-for-libssh/109766/1 "2024-02-05T21:40:39Z")

</div>

Heyo heyo 👋

So I’ve been working on writing a wrapper for the [libssh](https://www.libssh.org/) library recently, and I think it’s ready-ish enough for others to use (if they dare 🐙).

Source: [GitHub - JuliaWeb/LibSSH.jl: A Julia wrapper for libssh.](https://github.com/JuliaWeb/LibSSH.jl)  
Docs: [https://juliaweb.github.io/LibSSH.jl](https://juliaweb.github.io/LibSSH.jl)

TL;DR: this lets you do SSH things programmatically. Here’s a peek of the API:

```julia
import LibSSH as ssh

session = ssh.Session("foo.com")
ssh.userauth_password(session, "password")
close(session)

```

And a bigger example here: [Examples · LibSSH](https://juliaweb.github.io/LibSSH.jl/stable/examples/)

Libssh (the C library) can work in both a blocking and non-blocking mode. LibSSH.jl sets everything to use the non-blocking mode by default and it’s fully compatible with Julia’s event loop, so you can safely call all of the _high-level_ functions without needing to worry about them blocking. The [_low-level_ functions](https://juliaweb.github.io/LibSSH.jl/stable/bindings/) are pure wrappers to the C functions and may block or otherwise do strange things (check the excellent [libssh docs](https://api.libssh.org/stable/) before using them).

Disclaimer: the package is still young and there may be bugs and missing functionality 🙃 (well ok, there’s definitely lots of missing functionality)  
Having said that, the implementation of the SSH protocol itself is entirely delegated to libssh, which is a fairly trusted library, so I’m mildly confident that there’s at least no severe security issues.

---

<div class="post-metadata">

**Author:** ![JamesNZ](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jamesnz/32/35361_2.png) [@JamesNZ](https://discourse.julialang.org/u/JamesNZ)\
**Post date:** [October 11, 2024, 4:22pm UTC](https://discourse.julialang.org/t/ann-libssh-jl-a-julia-wrapper-for-libssh/109766/2 "2024-10-11T16:22:49Z")

</div>

[v0.6.0](https://juliaweb.github.io/LibSSH.jl/stable/generated_changelog/#%5Bv0.6.0%5D(https://github.com/JuliaWeb/LibSSH.jl/releases/tag/v0.6.0)-2024-10-11) has been released, the big change for this one is SFTP support so you can do terrible things to remote files: [SFTP · LibSSH](https://juliaweb.github.io/LibSSH.jl/stable/sftp/)

---

<div class="post-metadata">

**Author:** ![JamesNZ](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jamesnz/32/35361_2.png) [@JamesNZ](https://discourse.julialang.org/u/JamesNZ)\
**Post date:** [July 5, 2026, 12:01pm UTC](https://discourse.julialang.org/t/ann-libssh-jl-a-julia-wrapper-for-libssh/109766/3 "2026-07-05T12:01:32Z")

</div>

v1 has been released: [Changelog · LibSSH](https://juliaweb.github.io/LibSSH.jl/stable/generated_changelog/#%5Bv1.0.0%5D(https://github.com/JuliaWeb/LibSSH.jl/releases/tag/v1.0.0)-2026-06-25)  
The main improvement is thread-safety, it should now be safe to use LibSSH.jl objects without caring about which thread/task is making calls.

---

<div class="post-metadata">

**Author:** ![JamesNZ](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jamesnz/32/35361_2.png) [@JamesNZ](https://discourse.julialang.org/u/JamesNZ)\
**Post date:** [July 23, 2026, 10:36am UTC](https://discourse.julialang.org/t/ann-libssh-jl-a-julia-wrapper-for-libssh/109766/4 "2026-07-23T10:36:08Z")

</div>

v1.2.0 has been released, and I strongly recommend that folks update to it because it has some security fixes. See the changelog for details: [Changelog · LibSSH](https://juliaweb.github.io/LibSSH.jl/stable/generated_changelog/#%5Bv1.2.0%5D(https://github.com/JuliaWeb/LibSSH.jl/releases/tag/v1.2.0)-2026-07-23)

- If you use LibSSH.jl at all you should update to at least v1.1.0 because that uses the upstream [libssh 0.12.1](https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/), which has a bunch of security fixes compared to the previous version (0.11).
- If you were using the SFTP features of LibSSH.jl then you _really_ should update to v1.2.0 because that has some security fixes in LibSSH.jl itself.

---

<div class="post-metadata">

**Author:** ![mbauman](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/mbauman/32/31082_2.png) [@mbauman](https://discourse.julialang.org/u/mbauman)\
**Post date:** [July 23, 2026, 4:15pm UTC](https://discourse.julialang.org/t/ann-libssh-jl-a-julia-wrapper-for-libssh/109766/5 "2026-07-23T16:15:27Z")

</div>

That’s great! I’ve [published the libssh\_jll security advisories](https://julialang.github.io/SecurityAdvisories.jl/packages/libssh_jll/); you may consider [authoring a JLSEC advisory](https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/CONTRIBUTING.md) for those SFTP issues in LibSSH.jl itself — let me know if you have any questions about doing so! The main advantage in doing this is that it really helps communicate the issue to people who are using a security scanning tool.
