Binaries in these bundles
Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools.
Which source has a given CPU varies from release to release - nodejs.org
builds some architectures, unofficial-builds others, and the
wekan/node-patches build the ones
neither of them does - and not every source publishes a checksum. This is
what went into this release, and which downloads were checked against a
published SHA256.
| Bundle | Binary | From | Version | Checked | SHA256 |
|---|---|---|---|---|---|
| amd64 | FerretDB | wekan/FerretDB | v1.71.0 | verified | 588b81faa6049d3b…
|
| amd64 | Node.js | nodejs.org | v24.20.0 | verified | 2f2c0da162318f0d…
|
| arm64 | FerretDB | wekan/FerretDB | v1.71.0 | verified | 34b0858526c9aa1a…
|
| arm64 | Node.js | nodejs.org | v24.20.0 | verified | 5f4ddab610c1ab20…
|
| armhf | FerretDB | wekan/FerretDB | v1.71.0 | verified | 1597842dbad151bd…
|
| armhf | Node.js | wekan/node-patches | v24.20.0 | verified | b8ed7065d44f0afe…
|
| armv6 | FerretDB | wekan/FerretDB | v1.71.0 | verified | a98992a211d1302d…
|
| armv6 | Node.js | wekan/node-patches | v24.20.0 | verified | d5cefa6f8cc4acb1…
|
| armv7 | FerretDB | wekan/FerretDB | v1.71.0 | verified | 1597842dbad151bd…
|
| armv7 | Node.js | wekan/node-patches | v24.20.0 | verified | c04c81e539347f39…
|
| i386 | FerretDB | wekan/FerretDB | v1.71.0 | verified | f3bc7e4c915e10c6…
|
| i386 | Node.js | wekan/node-patches | v24.20.0 | verified | bb44927307460dcf…
|
| mac-arm64 | FerretDB | wekan/FerretDB | v1.71.0 | verified | d10ab602d8299655…
|
| mac-arm64 | Node.js | nodejs.org | v24.20.0 | verified | b7bf7707070b950b…
|
| mac-x64 | FerretDB | wekan/FerretDB | v1.71.0 | verified | 8cbb7d2957be662d…
|
| mac-x64 | Node.js | nodejs.org | v24.20.0 | verified | 26fc30891004603d…
|
| ppc64le | FerretDB | wekan/FerretDB | v1.71.0 | verified | e96028e8886454a3…
|
| ppc64le | Node.js | nodejs.org | v24.20.0 | verified | 341307dcee20d883…
|
| riscv64 | FerretDB | wekan/FerretDB | v1.71.0 | verified | b391572ddd1b3f60…
|
| riscv64 | Node.js | unofficial-builds.nodejs.org | v24.20.0 | verified | a149c5bf85f98ff1…
|
| s390x | FerretDB | wekan/FerretDB | v1.71.0 | verified | 8d4d865a3447524f…
|
| s390x | Node.js | nodejs.org | v24.20.0 | verified | ca381121cb5a8d38…
|
| win-arm64 | FerretDB | wekan/FerretDB | v1.71.0 | verified | 0b73fa1b2c87f5a0…
|
| win-arm64 | Node.js | nodejs.org | v24.20.0 | verified | 31c6799744de8a54…
|
| win64 | FerretDB | wekan/FerretDB | v1.71.0 | verified | bf5a6581d2218623…
|
| win64 | Node.js | nodejs.org | v24.20.0 | verified | 6cac9ffbca8f6a47…
|
A row saying no checksum published is not a failed check - it is a
source that publishes nothing to check against. Those are the ones worth
fixing at the source.
v11.55 2026-09-07 WeKan ® release
In short: Legacy HTML4 is reverted, restoring the standard Meteor browser
interface. Local branding images, searchable document previews, browser lazy
loading, translation updates and the session-upgrade fix remain. Meteor tests
compile, and authentication forms follow keyboard order. Swimlane and card
controls regain their previous colors, and upgraded sessions retain their profile
without a duplicate login.
| Platform | Binary | From | Version | SHA256 |
|---|---|---|---|---|
| amd64 | Node.js | nodejs.org | v24.19.0 | 14b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
|
| amd64 | FerretDB | wekan/FerretDB | v1.53.0 | eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d
|
| arm64 | Node.js | nodejs.org | v24.19.0 | 01443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
|
| arm64 | FerretDB | wekan/FerretDB | v1.53.0 | bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da
|
| mac-arm64 | Node.js | nodejs.org | v24.19.0 | 3f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
|
| mac-arm64 | FerretDB | wekan/FerretDB | v1.53.0 | cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e
|
| mac-x64 | Node.js | nodejs.org | v24.19.0 | d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
|
| mac-x64 | FerretDB | wekan/FerretDB | v1.53.0 | d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3
|
This release reverts Legacy HTML4 and retains the following changes:
Browser interface - standard Meteor pages and deferred browser code.
Revert the client styling from the swimlane title-color matching change and the Updated source guards cover the restored colors and retained card palette. The earlier session-upgrade repair repeated a token login that Accounts had Move the existing credential and expiry into Accounts' memory store, remove its Unit scenarios cover completed and pending initial logins and cookie-only The Upcoming coverage audit ran all Node suites: 858 checks passed, with the Remove the Legacy HTML4 and Legacy Omi progressive browser interface, its Intervening translation updates, backup screenshots, session-upgrade repairs, The Node suite run and targeted reruns pass apart from two failures reproduced HTML export and its ZIP writer now load only after the HTML Export action is Trello package import no longer relies on an undeclared JSZip copy. It uses theRestore independent swimlane and card control colors. Thanks to Alishara and xet7.
card title-color matching change. Swimlane controls again use neutral gray and
darker hover colors, and card controls regain their previous styling. Remove the
shared card-control class and the added light-card title overrides.
Four live checks in Chromium and Firefox verify swimlane normal/hover colors and
card controls on colored backgrounds at testi.wekan.fi.
Keep upgraded session profiles without a duplicate login. Thanks to Alishara and xet7.
already started. Live DDP diagnostics reproduced the remaining symptoms of
#6677: the user ID remained logged
in, but rebuilding subscriptions cleared the published profile. The saved
profile in the database was unchanged. This is separate from control CSS.
old persistent copy, synchronize the token poll and let the native validated
endpoint set the HttpOnly cookie. Do not repeat the initial login. Cookie-only
clients continue using the native cookie resume.
startup. The extended live regression checks the name, loaded avatar and theme
past the three-second poll, edits the name and theme, favorites the board,
switches to list view and verifies persistence after a cookie-only reload.
Both Chromium and Firefox pass this regression and the private-board refresh
check. Native Edge, AD authentication and WebKit were not exercised.
same two pre-existing failures for an undocumented test-results directory and
Finnish rule-description wording. All three targeted color/session suites pass.
Revert Legacy HTML4. Thanks to xet7.
cookieless sessions, page controllers, assets and parity refactors. Page requests
again use the standard Meteor interface and the previous browser operations.
The HTML4 design documents, paused-work backlog and feature tests are removed.
cryptographic test identifiers, local image storage, searchable document previews
and browser lazy loading remain. Shared GIF utilities now live in an independent
image module so the retained image features have no HTML4 dependency.
with the previous code: an undocumented existing test-results directory and a
Finnish rule-description expectation. Five new interface and image checks pass;
121 changed application modules parse and their 1,001 local imports resolve.
Live validation at testi.wekan.fi passes eight checks in Chromium and
Firefox: standard sign-in, JavaScript-disabled responses, member board loading
and non-member denial. WebKit cannot launch with the available system libraries.
Existing suites cover the retained Upcoming features, session repair, build fix,
keyboard navigation and email documentation.
Lazy-load browser export code and share its ZIP implementation. Thanks to xet7.
clicked. The direct JSZip dependency is removed; export uses the same small MIT
fflate implementation as server-side document conversion, while ZIP imports
continue through the bounded streaming server route. Gantt no longer imports an
unused Markdown parser, and attachment UI no longer loads BSON merely to create
or display an identifier. Tests keep the feature boundary dynamic, prevent the
duplicate ZIP library from returning, and cover the import/export paths.
Share the streaming ZIP reader with Trello imports. Thanks to xet7.
same server-side unzipper reader as the bounded backup and scoped-import paths,
while retaining path, entry-count, expanded-size and per-file limits. This leaves
fflate as the small lazy browser/document ZIP implementation and unzipper as
the server reader for large streamed input.
Sign in and sign up - keyboard order and session continuity.
Upgrading from v11.39 no longer replaces the browser's existing resume-token Static positive and negative coverage pins the migration order and forbids Tab now moves directly from each sign-in or sign-up writing field to the nextKeep profiles and preferences through session upgrades. Thanks to Alishara and xet7.
store before that token has migrated to the new HttpOnly cookie flow. The
three-second Accounts token poll therefore cannot log out the restored user and
remove their reactive name, avatar, theme, favorites and board-view settings.
direct token writes. A Chromium regression recreates the old local-token state,
checks the profile and board view, and remains logged in beyond the poll window.
Fix authentication form keyboard navigation. Thanks to xet7.
one below it without stopping on a show/hide-password control. The controls
remain available by pointer and assistive technology. Native Enter submission
remains active in the bottom field. Source and three-browser tests cover the
positive field order, the skipped controls, failed-login submission and
successful account creation.
Images and attachments - local images and searchable document previews.
PDF, DOCX, XLSX and PPTX previews are now generated on the server and cached in Source bytes, decoded text, page count, archive entries and expanded OOXML data are Admin Panel instance and Organization branding now offers image upload controls At startup, existing external login logos, header logos and board backgrounds areStore searchable document text and GIF attachment previews. Thanks to xet7.
Default Storage. Plain Unicode text is stored without formatting in a separate
unpublished searchText field, displayed as selectable text, and exposed to a
board-authorized attachment-text search method. Embedded document images and PDF
page imagery are converted to GIF; page controls browse the combined lightweight
representation.
all bounded. ZIP entries are streamed, malformed images do not suppress readable
text, generated data is tied to the original checksum, and every manifest, image
and search request repeats board-read authorization. The small conversion stack is
MIT and Apache-2.0 only; no GPL, LibreOffice, Ghostscript, browser runtime or OCR
dependency is added. Tests cover the storage split, authorization, regex escaping,
selectable safe rendering, GIF routes, size limits, licenses and vulnerable-version
exclusions. Sharp is updated to 0.35.4 so untrusted image decoding also receives the
current libvips security fixes.
Store branding and board background images locally as GIF. Thanks to xet7.
instead of editable external image URL fields. Every upload is authorized, bounded,
decoded and converted to GIF on the server before it is written to Admin Panel /
Attachments / Default Storage. Direct REST and tenant-setting writes cannot restore
an arbitrary image source URL. The separately configured logo click destination is
unchanged.
downloaded through the SSRF-safe fetcher, converted to GIF and atomically replaced
with internal URLs. A failed legacy download is removed immediately from client-
visible data and retained only in an unpublished retry queue for the next startup.
Board Settings likewise offers only upload, unset and the stored-background list;
new board backgrounds pass through a board-admin-checked GIF conversion method.
Offline imports no longer activate third-party background URLs. Regression coverage
checks authorization, input limits, SSRF-safe migration, Default Storage selection,
GIF-only output, response hardening, hidden URL write paths, board-background upload
and import behavior.
Tests and build - compilation and secure test identifiers.
Playwright readiness selects HTTPS for a public HTTPS test URL. The board All Playwright fixture usernames, addresses, object identifiers and run markers A source regression scans every Playwright helper and specification, requires The isomorphic change-history integrity helper now computes synchronous SHA-256Verify the restored browser interface over HTTPS. Thanks to xet7.
non-member regression waits for the rendered denial and absence of the canvas,
so the development server's persistent SockJS polling cannot cause a false
network-idle timeout. The HTTPS guard and eight live Chromium/Firefox checks pass.
Use cryptographic randomness throughout Playwright tests. Thanks to xet7.
now come from one Node crypto.randomBytes helper instead of Math.random.
This resolves CodeQL alerts 450 through 522 and prevents predictable randomness
from becoming normalized in tests that exercise authentication and authorization
boundaries.
the shared helper to remain CSPRNG-backed and refuses any executable
Math.random() call. The retained files pass JavaScript syntax checks; the removed HTML4 browser
specifications no longer form part of this coverage.
Fix the Meteor client test bundle. Thanks to xet7.
without importing Node crypto, so client tests no longer pull in
crypto-browserify and fail on its unresolved vm and stream modules. Test
vectors compare the implementation with Node's SHA-256, and the compiled client
source map is free of the former dependency chain. The language-loading test
now checks i18next state without a dynamic require warning. Test-run signal
handlers disarm themselves before cleanup, preventing repeated Ctrl-C presses
from recursively restarting port cleanup.
Documentation - deployment email configuration.
Snap help, every current Docker Compose example, Unix and Windows start scripts,Document Admin Panel email configuration. Thanks to xet7.
and the VirtualBox launcher now explain above MAIL_URL that enabling Enable
below email settings at Admin Panel / People / Email reveals the additional
email sending options. A regression check keeps that guidance present and in
the correct order across every deployment example.
Thanks to above GitHub users for their contributions and translators for their
translations.