Wekan logo

Wekan

Open source kanban board application built with Meteor

Alternative to: trello


About Versions (218)

v10.73

2026-08-08

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node fork the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

BundleBinaryFromVersionCheckedSHA256
arm64FerretDBwekan/FerretDBlatestverifiedb4a627780b746988…
arm64FerretDBwekan/FerretDBlatestverifiedb4a627780b746988…
arm64Node.jsnodejs.orgv24.19.0verified01443c1e1a29e531…
arm64Node.jsnodejs.orgv24.19.0verified01443c1e1a29e531…
armhfFerretDBwekan/FerretDBlatestverified82c4f226202e1038…
armhfFerretDBwekan/FerretDBlatestverified82c4f226202e1038…
armhfNode.jswekan/node-patchesv24.19.0verifiedb55350f3071b765a…
armhfNode.jswekan/node-patchesv24.19.0verifiedb55350f3071b765a…
armv7FerretDBwekan/FerretDBv1.46.0verified82c4f226202e1038…
armv7FerretDBwekan/FerretDBv1.46.0verified82c4f226202e1038…
armv7Node.jswekan/node-patchesv24.19.0verified8dbe0a9aa8550ad5…
armv7Node.jswekan/node-patchesv24.19.0verified8dbe0a9aa8550ad5…
i386FerretDBwekan/FerretDBv1.46.0verified0d2f948e0337e5b1…
i386FerretDBwekan/FerretDBv1.46.0verified0d2f948e0337e5b1…
i386Node.jswekan/node-patchesv24.19.0verified3b0b3bbfe27daf58…
i386Node.jswekan/node-patchesv24.19.0verified3b0b3bbfe27daf58…
mac-arm64FerretDBwekan/FerretDBlatestverified063c66968a5d0d84…
mac-arm64FerretDBwekan/FerretDBlatestverified063c66968a5d0d84…
mac-arm64Node.jsnodejs.orgv24.19.0verified3f1cf157479c1480…
mac-arm64Node.jsnodejs.orgv24.19.0verified3f1cf157479c1480…
ppc64leFerretDBwekan/FerretDBv1.46.0verified9ced5b800d82d184…
ppc64leFerretDBwekan/FerretDBv1.46.0verified9ced5b800d82d184…
ppc64leNode.jsnodejs.orgv24.19.0verifiedc510c6ce12f07010…
ppc64leNode.jsnodejs.orgv24.19.0verifiedc510c6ce12f07010…
riscv64FerretDBwekan/FerretDBv1.46.0verifiedd1bcfde0227c68d9…
riscv64FerretDBwekan/FerretDBv1.46.0verifiedd1bcfde0227c68d9…
riscv64Node.jsunofficial-builds.nodejs.orgv24.19.0verifiedcd1f14af28121480…
riscv64Node.jsunofficial-builds.nodejs.orgv24.19.0verifiedcd1f14af28121480…
s390xFerretDBwekan/FerretDBv1.46.0verified62bae6c40e1ad486…
s390xFerretDBwekan/FerretDBv1.46.0verified62bae6c40e1ad486…
s390xNode.jsnodejs.orgv24.19.0verifieda4792e65962ffa0a…
s390xNode.jsnodejs.orgv24.19.0verifieda4792e65962ffa0a…
win64FerretDBwekan/FerretDBlatestverified508dbd2f26469fc1…
win64FerretDBwekan/FerretDBlatestverified508dbd2f26469fc1…
win64Node.jsnodejs.orgv24.19.0verified57f71ab3652e797d…
win64Node.jsnodejs.orgv24.19.0verified57f71ab3652e797d…

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v10.73 2026-08-08 WeKan ® release

In short: a GitHub CodeQL finding fixed after v10.72 was tagged - PatternBleed, a string replacement that replaced a hyphen with itself, so an escape that looked like one was not there - and a guard that catches the whole class in WeKan’s own test run rather than days later in a web interface. The binaries below are v10.72’s: nothing here rebuilds them.

PlatformBinaryFromVersionSHA256
amd64Node.jsnodejs.orgv24.19.014b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
amd64FerretDBwekan/FerretDBv1.45.094713f605167abb45a3717482d35de4824cb4a8f199c1400e826a8a2b04f3893
arm64Node.jsnodejs.orgv24.19.001443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
arm64FerretDBwekan/FerretDBv1.45.0275ae50ac97e6a70eee72e6de37766c458775c5997c896352db5189c6cf1f04b
loong64Node.jsunofficial-builds.nodejs.orgv24.19.0c24f224726f2d785bd18a1fd09f5e6d1fecf0269928451a60c5da9eac8e92e68
loong64FerretDBwekan/FerretDBv1.45.028bf67981168dfc4bd67698b41dd62628aafe347a77f2b1e6ffcadf009d575e0
mac-arm64Node.jsnodejs.orgv24.19.03f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
mac-arm64FerretDBwekan/FerretDBv1.45.0639ed58b84820b3d588f4161c64d0ab940d0cc6e7d022088d60c2b0b97f99f8e
mac-x64Node.jsnodejs.orgv24.19.0d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
mac-x64FerretDBwekan/FerretDBv1.45.0fd519903f5630e881e38e7c5814f00c0e89ad26f6785f1ddcbab4058356fc9f3
ppc64leNode.jsnodejs.orgv24.19.0c510c6ce12f07010f771e6edb22a3fe23f4f2e6f40b1ffd4941aed0646a0d8b3
ppc64leFerretDBwekan/FerretDBv1.45.0de4518c7774d302533369c477759ddd866785d6741d98d399388eb8de3df175a
riscv64Node.jsunofficial-builds.nodejs.orgv24.19.0cd1f14af2812148002f58b58a5f9af512a50e3b8e8c148e0db44019dcb68edfd
riscv64FerretDBwekan/FerretDBv1.45.07dc2952f554e8800c4029577901999e06e10272da686f7e402177080067028f9
s390xNode.jsnodejs.orgv24.19.0a4792e65962ffa0af42627aacf1122a60c3c88dbf4e4184f06820d66f9da8ba4
s390xFerretDBwekan/FerretDBv1.45.00ae2e2f2cffdc5dd2ea4f125281a5e12eea216fbe49b5561d9c001700c3fc0c1
win64Node.jsnodejs.orgv24.19.057f71ab3652e797d84acddc79c81cc9ff1c6ddb2a1974cdb83f00fee9bff4c73
win64FerretDBwekan/FerretDBv1.45.0f6337994368a52d011d438c82b914b0cedb3178fd030acac8db3dab8017cee85

This release fixes the following SECURITY ISSUE found by GitHub CodeQL code scanning:

PatternBleed: a string replacement that replaced a hyphen with itself, and a guard for the whole class. Thanks to GitHub CodeQL code scanning and xet7.

PatternBleed - code scanning alert #431, rule js/identity-replacement (CWE-116), in tests/releaseNodeSources.test.cjs: a platform name was interpolated into a regex through p.replace('-', '-'), which replaces a hyphen with a hyphen. It reads as “escape this before putting it in a pattern” and does nothing at all, so the value went in raw.

Nothing failed, because a hyphen outside a character class needs no escaping - but the guard it looked like was not there, and a platform name carrying a . or a + would have matched the wrong row or thrown. CodeQL is right to flag the shape: its usual cause is a mistyped backslash escape, where a replacement meant to double a character silently is that character. The name is escaped for real now, with the same escapeRegExp the other guards in tests/ use.

tests/noIdentityReplacement.test.cjs catches the class rather than the instance - code scanning reports these days later in a web UI, the node suites report in fifteen seconds. Three things it took to make it honest: it compares the two sides as VALUES rather than as source text, since an escaped quote and a plain one are the same value and a text comparison would miss the very mistake it exists for; the two quote styles are separate alternatives rather than one character class excluding both, because CodeQL’s own example puts a double quote inside a single-quoted literal and the first shape of the pattern could not match it; and comments are stripped, with the guard skipping its own file, because this file and the one it was written for both quote the bad line to explain it. Verified in both directions - the repository is clean, and the same scan against the previous commit reports the offending line.

Thanks to above GitHub users for their contributions and translators for their translations.