Download Latest Version wekan-11.72-s390x.zip (286.8 MB)
Email in envelope

Get an email when there's a new version of wekan

Home / v10.60
Name Modified Size InfoDownloads / Week
Parent folder
wekan-10.60-sandstorm.spk 2026-08-04 171.2 MB
README.md 2026-08-04 3.4 kB
v10.60 source code.tar.gz 2026-08-04 34.0 MB
v10.60 source code.zip 2026-08-04 35.3 MB
Totals: 4 Items   240.5 MB 0

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node fork the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

Bundle Binary From Version Checked SHA256
arm64 FerretDB wekan/FerretDB latest no checksum published
arm64 FerretDB wekan/FerretDB latest no checksum published
arm64 Node.js GitHub runner (setup-node) v22.23.1 no checksum published
arm64 Node.js GitHub runner (setup-node) v22.23.1 no checksum published

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v10.60 2026-08-04 WeKan ® release

In short: this release fixes the release workflow that publishes WeKan. The v10.59 release job built the GitHub Release body from the newest CHANGELOG section by interpolating it inline into a shell printf, so every backtick in the notes ran as a command — and v10.59's notes are full of code spans, so the job died with Incorrect: command not found and loginFailureDecision.js: Permission denied, and published nothing. The CHANGELOG now reaches the release-notes scripts through the environment, where the shell treats it as data. A new test pins that the changelog is never interpolated into a run: script again.

This release fixes the following release-build issue:

The release notes pass the CHANGELOG through the environment instead of inline into the shell. Thanks to xet7. The `release` and `release-notes` jobs of `release-all.yml` composed the GitHub Release body with `printf '%s\n' "${{ needs.prepare.outputs.changelog }}"`. Interpolated inline with `${{ }}`, the CHANGELOG becomes part of the shell *source* before bash parses it, so a backtick in an entry — every `code` span is one — runs as a command substitution. The v10.59 notes (this file's own LockoutBleed section) turned into `Incorrect: command not found`, `User not found: command not found`, `POST: command not found` and `server/apiAuthRoutes.js: Permission denied`, the `release` job failed, and the release was published with no bundles. Both steps now take the changelog through `env: CHANGELOG: ${{ … }}` and write `"$CHANGELOG"`, where the shell treats the value as data and never parses its backticks, `$( )` or quotes. `tests/releaseNotesNoShellInjection.test.cjs` pins that `outputs.changelog` is only ever consumed as an `env:` assignment, never inline in a `run:` script, and fails on both pre-fix `printf` lines.

Thanks to above GitHub users for their contributions and translators for their translations.

Source: README.md, updated 2026-08-04