Wekan
Open source kanban board application built with Meteor
Alternative to: trello
v11.53
2026-09-05Binaries in these bundles
Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.
| Bundle | Binary | From | Version | Checked | SHA256 |
|---|---|---|---|---|---|
| amd64 | FerretDB | wekan/FerretDB | v1.69.0 | verified | d45247243ee7c377… |
| amd64 | Node.js | nodejs.org | v24.20.0 | verified | 2f2c0da162318f0d… |
| arm64 | FerretDB | wekan/FerretDB | v1.69.0 | verified | c55a1e610ea3af12… |
| arm64 | Node.js | nodejs.org | v24.20.0 | verified | 5f4ddab610c1ab20… |
| armhf | FerretDB | wekan/FerretDB | v1.69.0 | verified | 53697744857c4904… |
| armhf | Node.js | wekan/node-patches | v24.20.0 | verified | b8ed7065d44f0afe… |
| armv6 | FerretDB | wekan/FerretDB | v1.69.0 | verified | a4e7ed0c2a1d4df9… |
| armv6 | Node.js | wekan/node-patches | v24.20.0 | verified | d5cefa6f8cc4acb1… |
| armv7 | FerretDB | wekan/FerretDB | v1.69.0 | verified | 53697744857c4904… |
| armv7 | Node.js | wekan/node-patches | v24.20.0 | verified | c04c81e539347f39… |
| i386 | FerretDB | wekan/FerretDB | v1.69.0 | verified | 7e42b7ba806f0a4a… |
| i386 | Node.js | wekan/node-patches | v24.20.0 | verified | bb44927307460dcf… |
| mac-arm64 | FerretDB | wekan/FerretDB | v1.69.0 | verified | 6276ee96db710a8d… |
| mac-arm64 | Node.js | nodejs.org | v24.20.0 | verified | b7bf7707070b950b… |
| mac-x64 | FerretDB | wekan/FerretDB | v1.69.0 | verified | ab7c80ad4d62c1f1… |
| mac-x64 | Node.js | nodejs.org | v24.20.0 | verified | 26fc30891004603d… |
| ppc64le | FerretDB | wekan/FerretDB | v1.69.0 | verified | f49ef5cf05d35ef1… |
| ppc64le | Node.js | nodejs.org | v24.20.0 | verified | 341307dcee20d883… |
| riscv64 | FerretDB | wekan/FerretDB | v1.69.0 | verified | 3dabafcbe5f48bd4… |
| riscv64 | Node.js | unofficial-builds.nodejs.org | v24.20.0 | verified | a149c5bf85f98ff1… |
| s390x | FerretDB | wekan/FerretDB | v1.69.0 | verified | 25c08eb34c8fe0f2… |
| s390x | Node.js | nodejs.org | v24.20.0 | verified | ca381121cb5a8d38… |
| win-arm64 | FerretDB | wekan/FerretDB | v1.69.0 | verified | 65474b87bf0e4679… |
| win-arm64 | Node.js | nodejs.org | v24.20.0 | verified | 31c6799744de8a54… |
| win64 | FerretDB | wekan/FerretDB | v1.69.0 | verified | ae3f8c4e2697b75d… |
| win64 | Node.js | nodejs.org | v24.20.0 | verified | 6cac9ffbca8f6a47… |
A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.
v11.53 2026-09-06 WeKan ® release
In short: Amiga-safe filenames are sanitized before upload and whenever they are displayed or downloaded, retain content-correct application extensions, and avoid truncating through brackets. Existing stored names are corrected lazily when read. Problems reports retain available usernames, separate IPv4/IPv6 addresses, and proxy-provided country and city context. Security regression tests also avoid embedding incomplete sanitizer examples.
| Platform | Binary | From | Version | SHA256 |
|---|---|---|---|---|
| amd64 | Node.js | nodejs.org | v24.19.0 | 14b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647 |
| amd64 | FerretDB | wekan/FerretDB | v1.53.0 | eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d |
| arm64 | Node.js | nodejs.org | v24.19.0 | 01443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc |
| arm64 | FerretDB | wekan/FerretDB | v1.53.0 | bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da |
| mac-arm64 | Node.js | nodejs.org | v24.19.0 | 3f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94 |
| mac-arm64 | FerretDB | wekan/FerretDB | v1.53.0 | cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e |
| mac-x64 | Node.js | nodejs.org | v24.19.0 | d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4 |
| mac-x64 | FerretDB | wekan/FerretDB | v1.53.0 | d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3 |
This release fixes the following SECURITY ISSUES found by GitHub CodeQL code scanning:
Remove incomplete sanitizer test doubles. Thanks to GitHub CodeQL and xet7.
The import/export boundary regression test no longer demonstrates a partial
regular-expression sanitizer that handled only one URL scheme and complete HTML
tags. Its deterministic observation callback now proves that HTML and
javascript:, vbscript: and data: payloads reach the sanitizer boundary,
while the production callback remains DOMPurify. This resolves CodeQL alerts
448 and 449 without creating a misleading sanitizer example. The findings were
confined to test code and exposed no runtime path, so there is no attributable
security event to report in Admin Panel Problems or researcher to add to the
Hall of Fame.
Files and problem reporting - Portable names and attributable diagnostics.
Enforce Amiga-safe filenames on every read. Thanks to xet7.
One common filename boundary now sanitizes names before upload and whenever a
name is displayed, archived or downloaded. It preserves the content-derived
extension inside the classic Amiga FFS 30-character limit and removes an
incomplete bracketed suffix instead of producing names such as
Online Gantt 20260905 (1.gantt. The maintained JavaScript file-type detector
handles binary magic bytes before the bounded libmagic/text fallback; Online
Gantt JSON retains its application-owned .gantt extension. Existing attachment
metadata is corrected only when an authorized read needs it, not by an eager
database-wide rename.
The common Problems fold now fills available usernames and obtains trusted, proxy-aware request addresses for all report streams. IPv4 and IPv6 remain separate, while available Cloudflare and other supported proxy/CDN headers add a display-only country flag, city, region and coordinates. DDP lockout reports now forward their known username, source address and headers instead of showing an empty actor beside “locked one address.” Location never participates in a security decision.