Wekan logo

Wekan

Open source kanban board application built with Meteor

Alternative to: trello


About Versions (307)

v11.53

2026-09-05

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

BundleBinaryFromVersionCheckedSHA256
amd64FerretDBwekan/FerretDBv1.69.0verifiedd45247243ee7c377…
amd64Node.jsnodejs.orgv24.20.0verified2f2c0da162318f0d…
arm64FerretDBwekan/FerretDBv1.69.0verifiedc55a1e610ea3af12…
arm64Node.jsnodejs.orgv24.20.0verified5f4ddab610c1ab20…
armhfFerretDBwekan/FerretDBv1.69.0verified53697744857c4904…
armhfNode.jswekan/node-patchesv24.20.0verifiedb8ed7065d44f0afe…
armv6FerretDBwekan/FerretDBv1.69.0verifieda4e7ed0c2a1d4df9…
armv6Node.jswekan/node-patchesv24.20.0verifiedd5cefa6f8cc4acb1…
armv7FerretDBwekan/FerretDBv1.69.0verified53697744857c4904…
armv7Node.jswekan/node-patchesv24.20.0verifiedc04c81e539347f39…
i386FerretDBwekan/FerretDBv1.69.0verified7e42b7ba806f0a4a…
i386Node.jswekan/node-patchesv24.20.0verifiedbb44927307460dcf…
mac-arm64FerretDBwekan/FerretDBv1.69.0verified6276ee96db710a8d…
mac-arm64Node.jsnodejs.orgv24.20.0verifiedb7bf7707070b950b…
mac-x64FerretDBwekan/FerretDBv1.69.0verifiedab7c80ad4d62c1f1…
mac-x64Node.jsnodejs.orgv24.20.0verified26fc30891004603d…
ppc64leFerretDBwekan/FerretDBv1.69.0verifiedf49ef5cf05d35ef1…
ppc64leNode.jsnodejs.orgv24.20.0verified341307dcee20d883…
riscv64FerretDBwekan/FerretDBv1.69.0verified3dabafcbe5f48bd4…
riscv64Node.jsunofficial-builds.nodejs.orgv24.20.0verifieda149c5bf85f98ff1…
s390xFerretDBwekan/FerretDBv1.69.0verified25c08eb34c8fe0f2…
s390xNode.jsnodejs.orgv24.20.0verifiedca381121cb5a8d38…
win-arm64FerretDBwekan/FerretDBv1.69.0verified65474b87bf0e4679…
win-arm64Node.jsnodejs.orgv24.20.0verified31c6799744de8a54…
win64FerretDBwekan/FerretDBv1.69.0verifiedae3f8c4e2697b75d…
win64Node.jsnodejs.orgv24.20.0verified6cac9ffbca8f6a47…

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v11.53 2026-09-06 WeKan ® release

In short: Amiga-safe filenames are sanitized before upload and whenever they are displayed or downloaded, retain content-correct application extensions, and avoid truncating through brackets. Existing stored names are corrected lazily when read. Problems reports retain available usernames, separate IPv4/IPv6 addresses, and proxy-provided country and city context. Security regression tests also avoid embedding incomplete sanitizer examples.

PlatformBinaryFromVersionSHA256
amd64Node.jsnodejs.orgv24.19.014b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
amd64FerretDBwekan/FerretDBv1.53.0eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d
arm64Node.jsnodejs.orgv24.19.001443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
arm64FerretDBwekan/FerretDBv1.53.0bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da
mac-arm64Node.jsnodejs.orgv24.19.03f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
mac-arm64FerretDBwekan/FerretDBv1.53.0cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e
mac-x64Node.jsnodejs.orgv24.19.0d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
mac-x64FerretDBwekan/FerretDBv1.53.0d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3

This release fixes the following SECURITY ISSUES found by GitHub CodeQL code scanning:

Remove incomplete sanitizer test doubles. Thanks to GitHub CodeQL and xet7.

The import/export boundary regression test no longer demonstrates a partial regular-expression sanitizer that handled only one URL scheme and complete HTML tags. Its deterministic observation callback now proves that HTML and javascript:, vbscript: and data: payloads reach the sanitizer boundary, while the production callback remains DOMPurify. This resolves CodeQL alerts 448 and 449 without creating a misleading sanitizer example. The findings were confined to test code and exposed no runtime path, so there is no attributable security event to report in Admin Panel Problems or researcher to add to the Hall of Fame.

Files and problem reporting - Portable names and attributable diagnostics.

Enforce Amiga-safe filenames on every read. Thanks to xet7.

One common filename boundary now sanitizes names before upload and whenever a name is displayed, archived or downloaded. It preserves the content-derived extension inside the classic Amiga FFS 30-character limit and removes an incomplete bracketed suffix instead of producing names such as Online Gantt 20260905 (1.gantt. The maintained JavaScript file-type detector handles binary magic bytes before the bounded libmagic/text fallback; Online Gantt JSON retains its application-owned .gantt extension. Existing attachment metadata is corrected only when an authorized read needs it, not by an eager database-wide rename.

The common Problems fold now fills available usernames and obtains trusted, proxy-aware request addresses for all report streams. IPv4 and IPv6 remain separate, while available Cloudflare and other supported proxy/CDN headers add a display-only country flag, city, region and coordinates. DDP lockout reports now forward their known username, source address and headers instead of showing an empty actor beside “locked one address.” Location never participates in a security decision.