Wekan logo

Wekan

Open source kanban board application built with Meteor

Alternative to: trello


About Versions (307)

v11.16

2026-08-27

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

BundleBinaryFromVersionCheckedSHA256
amd64FerretDBwekan/FerretDBv1.62.0verified42b6031e48a6a44c…
amd64Node.jsnodejs.orgv24.20.0verified2f2c0da162318f0d…
arm64FerretDBwekan/FerretDBv1.62.0verified930b33cbc83b35cb…
arm64Node.jsnodejs.orgv24.20.0verified5f4ddab610c1ab20…
armhfFerretDBwekan/FerretDBv1.62.0verified2963fdfc690f0cca…
armhfNode.jswekan/node-patchesv24.19.0verified46509e82e4f08d0d…
armv6FerretDBwekan/FerretDBv1.62.0verified58f2f6ddff05b951…
armv6Node.jswekan/node-patchesv24.19.0verified1a76291e8edfd5c0…
armv7FerretDBwekan/FerretDBv1.62.0verified2963fdfc690f0cca…
armv7Node.jswekan/node-patchesv24.19.0verified1303fbc89fb187c1…
i386FerretDBwekan/FerretDBv1.62.0verified96919f54f4dabb29…
i386Node.jswekan/node-patchesv24.19.0verifiedc94bc7fc2713b22c…
mac-arm64FerretDBwekan/FerretDBv1.62.0verifiedaf5707904580f34f…
mac-arm64Node.jsnodejs.orgv24.20.0verifiedb7bf7707070b950b…
mac-x64FerretDBwekan/FerretDBv1.62.0verified57dc580ad9b7a8bf…
mac-x64Node.jsnodejs.orgv24.20.0verified26fc30891004603d…
ppc64leFerretDBwekan/FerretDBv1.62.0verifiedc93d394f1ce56534…
ppc64leNode.jsnodejs.orgv24.20.0verified341307dcee20d883…
riscv64FerretDBwekan/FerretDBv1.62.0verified404bee52f8bb86fa…
riscv64Node.jsunofficial-builds.nodejs.orgv24.20.0verifieda149c5bf85f98ff1…
s390xFerretDBwekan/FerretDBv1.62.0verified7edbadece06a4921…
s390xNode.jsnodejs.orgv24.20.0verifiedca381121cb5a8d38…
win-arm64FerretDBwekan/FerretDBv1.62.0verified9318c87775c42b41…
win-arm64Node.jsnodejs.orgv24.20.0verified31c6799744de8a54…
win64FerretDBwekan/FerretDBv1.62.0verified25fec66a71c9fe50…
win64Node.jsnodejs.orgv24.20.0verified6cac9ffbca8f6a47…

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v11.16 2026-08-27 WeKan ® release

In short: Search pagination now binds every stored query to its authenticated owner, closing cross-board card disclosure through reused session IDs. The full release now publishes AppImages automatically after its core bundles, while 32-bit AppImages distinguish an unavailable runner from a broken package and keep i686 Node within its virtual-address-space limit. Card details regain their inner gutters, including on widened desktop panels. The table below is carried over from the release under this one, and is refilled from each build’s provenance.tsv when this release is made.

PlatformBinaryFromVersionSHA256
amd64Node.jsnodejs.orgv24.19.014b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
amd64FerretDBwekan/FerretDBv1.53.0eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d
arm64Node.jsnodejs.orgv24.19.001443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
arm64FerretDBwekan/FerretDBv1.53.0bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da
mac-arm64Node.jsnodejs.orgv24.19.03f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
mac-arm64FerretDBwekan/FerretDBv1.53.0cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e
mac-x64Node.jsnodejs.orgv24.19.0d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
mac-x64FerretDBwekan/FerretDBv1.53.0d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3

This release fixes the following CRITICAL SECURITY ISSUE of SessionBleed:

Search pagination sessions cannot be reused across users. Thanks to crypto-nidh and xet7.

The nextPage and previousPage DDP publications accepted a client-supplied global-search session ID, loaded its stored board selector without checking its owner, and could return private card titles, descriptions and custom-field values to a logged-out or different user. The session ID had to be obtained first, but neither publication enforced the authentication boundary.

Both paths now refuse logged-out clients and perform one owner-scoped lookup using the authenticated user and session ID together. Missing or foreign sessions complete without publishing data. Attributable logged-out probes are folded into a bounded SessionBleed summary in Admin Panel → Problems; ordinary authenticated pagination is never logged. Positive decision tests, a negative whole-publication scan and a live Chromium DDP test cover the boundary.

and fixes the following bugs:

AppImage packaging - 32-bit images start safely and report runner limits.

The 32-bit AppImages pass the right startup checks. Thanks to xet7.

The i686 launcher no longer gives a 32-bit Node process a 4 GiB V8 heap that exhausts its virtual address space while deserializing the startup snapshot. Automatic selection is capped at 1 GiB for an ELF 32-bit Node, while an explicit NODE_OPTIONS remains authoritative.

The armhf workflow now probes the Node binary inside the image instead of only the outer AppImage runtime. A runner whose kernel can execute the wrapper but lacks /lib/ld-linux-armhf.so.3 therefore uploads the package with an honest unchecked warning; a runnable Node must still pass the real HTTP smoke test. Positive and negative plain-Node coverage pins the heap ceiling, override, inner-runtime probe and smoke-test ordering.

Rebuilt 32-bit AppImages also protect older release bundles. Thanks to xet7.

The v11.15 rerun proved that fixing the bundle launcher alone was insufficient: an AppImage wraps the ZIP already attached to that release, so its bundled start-wekan.sh still predated the fix and i686 again died with GC during deserialization.

The generated AppRun now supplies the same 1 GiB V8 ceiling for i686 and armhf before invoking the bundle launcher. This makes a missing AppImage safely rebuildable around an older published ZIP, while ${NODE_OPTIONS} supplied by an administrator still wins. Regression coverage pins that old-bundle boundary and the architecture substitution.

The full release publishes its AppImages automatically. Thanks to xet7.

release-all.yml built and published the core ZIP bundles but never called the reusable AppImage workflow, leaving AppImages to a separate manual or missing-assets run. It now calls AppImage.yml immediately after the core GitHub Release has attached its amd64 and arm64 ZIPs. The exact new tag is passed explicitly, release-asset write permission is scoped to the call, and the work runs in parallel with the other post-release formats.

Regression coverage pins the release dependency, reusable-workflow path, tag, publish flag and permission, while the workflow-interface guard proves the called workflow exists and accepts every supplied input.

Card details - visible content stays inset at standard and custom widths.

Opened cards apply their side gutters to the visible content. Thanks to rmb82 and xet7.

An accessibility markup change accidentally made .card-details-canvas an empty sibling of the card header and body. Its computed 20-pixel padding still looked correct, but no visible content was inside it, so descriptions and custom fields touched the panel edges.

The canvas once again owns the whole card body. Positive and negative source coverage pins that ownership and rejects the empty-sibling structure, while the Playwright regression reproduces an 1100-pixel desktop panel and verifies the actual content-to-edge gaps rather than trusting the wrapper’s computed style.

Thanks to above GitHub users for their contributions and translators for their translations.