Download Latest Version wekan-11.72-s390x.zip (286.8 MB)
Email in envelope

Get an email when there's a new version of wekan

Home / v11.08
Name Modified Size InfoDownloads / Week
Parent folder
wekan_11.08_riscv64.snap 2026-08-23 201.6 MB
wekan_11.08_ppc64el.snap 2026-08-23 199.8 MB
wekan_11.08_armhf.snap 2026-08-22 186.9 MB
wekan_11.08_s390x.snap 2026-08-22 198.3 MB
wekan_11.08_amd64.snap 2026-08-22 409.4 MB
wekan_11.08_arm64.snap 2026-08-22 311.5 MB
wekan-11.08-riscv64.zip 2026-08-22 233.9 MB
wekan-11.08-riscv64.zip.sha256sum 2026-08-22 90 Bytes
wekan-11.08-ppc64le.zip 2026-08-22 235.4 MB
wekan-11.08-ppc64le.zip.sha256sum 2026-08-22 90 Bytes
wekan-11.08-s390x.zip 2026-08-22 236.4 MB
wekan-11.08-s390x.zip.sha256sum 2026-08-22 88 Bytes
wekan-11.08-armv6.zip 2026-08-22 222.5 MB
wekan-11.08-armv6.zip.sha256sum 2026-08-22 88 Bytes
wekan-11.08-armhf.zip 2026-08-22 221.5 MB
wekan-11.08-armhf.zip.sha256sum 2026-08-22 88 Bytes
wekan-11.08-armv7.zip 2026-08-22 221.5 MB
wekan-11.08-armv7.zip.sha256sum 2026-08-22 88 Bytes
wekan-11.08-sandstorm.spk 2026-08-22 137.2 MB
wekan-11.08-win-arm64.zip 2026-08-22 208.2 MB
wekan-11.08-win-arm64.zip.sha256sum 2026-08-22 92 Bytes
wekan-11.08-win64.zip 2026-08-22 218.7 MB
wekan-11.08-win64.zip.sha256sum 2026-08-22 88 Bytes
wekan-11.08-i386.zip 2026-08-22 227.9 MB
wekan-11.08-i386.zip.sha256sum 2026-08-22 87 Bytes
wekan-11.08-mac-x64.zip 2026-08-22 190.9 MB
wekan-11.08-mac-x64.zip.sha256sum 2026-08-22 90 Bytes
wekan-11.08-mac-arm64.zip 2026-08-22 226.2 MB
wekan-11.08-mac-arm64.zip.sha256sum 2026-08-22 92 Bytes
wekan-11.08-amd64.zip 2026-08-22 229.3 MB
wekan-11.08-amd64.zip.sha256sum 2026-08-22 88 Bytes
wekan-11.08-arm64.zip 2026-08-22 230.2 MB
wekan-11.08-arm64.zip.sha256sum 2026-08-22 88 Bytes
README.md 2026-08-22 20.6 kB
v11.08 source code.tar.gz 2026-08-22 41.1 MB
v11.08 source code.zip 2026-08-22 42.6 MB
Totals: 36 Items   4.6 GB 0

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

Bundle Binary From Version Checked SHA256
amd64 FerretDB wekan/FerretDB v1.54.0 verified cefef799be4d3abd…
amd64 Node.js nodejs.org v24.19.0 verified 14b342e71204f811…
arm64 FerretDB wekan/FerretDB v1.54.0 verified d6fc40d8657dc989…
arm64 Node.js nodejs.org v24.19.0 verified 01443c1e1a29e531…
armhf FerretDB wekan/FerretDB v1.54.0 verified 82e6a8e078b366ec…
armhf Node.js wekan/node-patches v24.19.0 verified b55350f3071b765a…
armv6 FerretDB wekan/FerretDB v1.54.0 verified 14da6f60445fcce2…
armv6 Node.js wekan/node-patches v24.19.0 verified 128ded0cda638c1f…
armv7 FerretDB wekan/FerretDB v1.54.0 verified 82e6a8e078b366ec…
armv7 Node.js wekan/node-patches v24.19.0 verified 8dbe0a9aa8550ad5…
i386 FerretDB wekan/FerretDB v1.54.0 verified e80b2672d833d38d…
i386 Node.js wekan/node-patches v24.19.0 verified 3b0b3bbfe27daf58…
mac-arm64 FerretDB wekan/FerretDB v1.54.0 verified cac5e99177cb9c98…
mac-arm64 Node.js nodejs.org v24.19.0 verified 3f1cf157479c1480…
mac-x64 FerretDB wekan/FerretDB v1.54.0 verified 6a12e289a83c32d4…
mac-x64 Node.js nodejs.org v24.19.0 verified d35e95230f46f6f0…
ppc64le FerretDB wekan/FerretDB v1.54.0 verified 1cdde969f9d888b9…
ppc64le Node.js nodejs.org v24.19.0 verified c510c6ce12f07010…
riscv64 FerretDB wekan/FerretDB v1.54.0 verified 748372f58a70a3d0…
riscv64 Node.js unofficial-builds.nodejs.org v24.19.0 verified cd1f14af28121480…
s390x FerretDB wekan/FerretDB v1.54.0 verified bb6028ef6fc61f86…
s390x Node.js nodejs.org v24.19.0 verified a4792e65962ffa0a…
win-arm64 FerretDB wekan/FerretDB v1.54.0 verified 37e005e17eb1c3c7…
win-arm64 Node.js nodejs.org v24.19.0 verified 8502f4a50b458d4c…
win64 FerretDB wekan/FerretDB v1.54.0 verified 870c892e7bcab272…
win64 Node.js nodejs.org v24.19.0 verified 57f71ab3652e797d…

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v11.08 2026-08-23 WeKan ® release

In short: six coordinated reports harden REST authorization, board ownership, administrator token auditing and error responses. Build and release tooling now supports macOS zsh, Alpine, Arch, Fedora, RHEL and Oracle Linux, keeps companion data under the repository's ignored .tools directory, provides sandbox-local tools, bounds build, test and runtime resources across every platform, reports resource failures in Admin Panel Problems, offers three bounded, cleanly interruptible complete-test execution modes, and includes four dependency updates.

Platform Binary From Version SHA256
amd64 Node.js nodejs.org v24.19.0 14b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
amd64 FerretDB wekan/FerretDB v1.53.0 eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d
arm64 Node.js nodejs.org v24.19.0 01443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
arm64 FerretDB wekan/FerretDB v1.53.0 bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da
mac-arm64 Node.js nodejs.org v24.19.0 3f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
mac-arm64 FerretDB wekan/FerretDB v1.53.0 cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e
mac-x64 Node.js nodejs.org v24.19.0 d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
mac-x64 FerretDB wekan/FerretDB v1.53.0 d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3

This release fixes the following HIGH AND MODERATE SECURITY ISSUES:

REST board mutations - cards, checklists, checklist items and comments.

Checklist mutations require board write access. Thanks to Char0n1507 and xet7. Checklist and checklist-item create, edit and delete routes accepted read-only board members because they checked only whether the caller could view the board. Every mutation now requires the canonical board write capability; read-only members retain GET access. See [GHSA-5r4m-5xx6-96jf](https://github.com/wekan/wekan/security/advisories/GHSA-5r4m-5xx6-96jf) and [ChecklistWriteBleed](https://wekan.fi/hall-of-fame/checklistwritebleed/).
Every REST mutation follows its canonical board-role capability. Thanks to senti-man and xet7. Checklist, checklist-item and comment routes had drifted from the role capability table: some mutations needed only read access, while comment creation required full write access and incorrectly rejected Comment Only members. Mutation routes now require write access and comment creation uses the comment capability. See [GHSA-cp24-5m9m-wm97](https://github.com/wekan/wekan/security/advisories/GHSA-cp24-5m9m-wm97) and [RoleBleed](https://wekan.fi/hall-of-fame/rolebleed/).
Card and checklist creation requires board write access. Thanks to Char0n1507 and xet7. Card and checklist creation reused the comment permission, allowing Comment Only members to create board content. Both single and bulk card creation and checklist creation now require the canonical write capability. See [GHSA-qf5c-63jx-mpv4](https://github.com/wekan/wekan/security/advisories/GHSA-qf5c-63jx-mpv4) and [CommentWriteBleed](https://wekan.fi/hall-of-fame/commentwritebleed/).

Boards - ownership assigned by the board-creation API.

REST board creation cannot choose another owner. Thanks to Char0n1507 and xet7. The board-creation route trusted the owner and role flags in the request body, so an authenticated caller could create a board attributed to another user. The authenticated caller is now always the initial active administrator and owner. See [GHSA-6jvj-85q3-6q2m](https://github.com/wekan/wekan/security/advisories/GHSA-6jvj-85q3-6q2m) and [OwnerBleed](https://wekan.fi/hall-of-fame/ownerbleed/).

Administrator API - issuing login tokens for another account.

Administrator-created login tokens require an audited reason. Thanks to Char0n1507 and xet7. The administrator token endpoint could create a reusable login token for another user without producing the impersonation audit record used by the normal UI. It now requires a reason, verifies the target, records the administrator and target before inserting the login token, and rejects an unaudited request. See [GHSA-5r57-9vj7-c64f](https://github.com/wekan/wekan/security/advisories/GHSA-5r57-9vj7-c64f) and [TokenAuditBleed](https://wekan.fi/hall-of-fame/tokenauditbleed/).

REST responses - safe status codes and public error messages.

REST failures return sanitized errors and correct HTTP statuses. Thanks to Char0n1507 and xet7. Board and user routes returned raw Error objects as successful HTTP 200 responses, which exposed implementation details and made failures look successful. Shared response handling now preserves expected 4xx statuses while replacing unexpected 5xx details with a generic message. Regression tests cover both paths and ensure raw errors do not return from the affected handlers. See [GHSA-h59p-76c3-8345](https://github.com/wekan/wekan/security/advisories/GHSA-h59p-76c3-8345) and [ErrorBleed](https://wekan.fi/hall-of-fame/errorbleed/).

and updates the following dependencies:

  • @aws-sdk/client-s3 3.1113.0 → 3.1114.0 — the Amazon S3 client.
  • @aws-sdk/lib-storage 3.1109.0 → 3.1114.0 — managed multipart uploads to S3.
  • @google-cloud/storage 7.22.0 → 8.0.1 — Google Cloud Storage integration.
  • dompurify 3.4.13 → 3.4.14 — HTML sanitization in the browser.

Thanks to dependabot.

and has the following developer-tooling improvements:

Build and release tooling - host setup and repository-local working data.

Every platform bounds runtime memory and reports resource failures. Thanks to xet7. Source builds, Linux and Windows bundles, Docker, Snap and Sandstorm now derive Node and FerretDB limits from available host or cgroup memory while preserving explicit administrator overrides. Test and Go compiler floors no longer exceed small containers, Playwright installs repository-local browsers and uses a matching Docker fallback when immutable host libraries are missing, and build dependency stderr remains visible in both the console and timestamped log. Runtime self-checks proactively report low disk space and V8 heap pressure in Admin Panel Problems. The database classifier now gives actionable reports for memory and file-descriptor exhaustion, read-only volumes, corruption and oversized documents. The remediation documents record which protections work on every platform and distinguish implemented FerretDB telemetry from follow-ups.
Complete tests offer two-worker, one-by-one and at-once modes. Thanks to xet7. The first three Tests menu choices in both `build.sh` and `build.bat` now run the whole matrix. The default runs one stage at a time with two Playwright workers per browser for a safe speed increase; one-by-one minimizes memory use; and at-once runs WeKan jobs concurrently. Database backends and FerretDB stages stay sequential in every mode to avoid port conflicts and overlapping compiler load. The Windows helper forwards the selected mode to the shared shell implementation, and parity tests pin the menu order, mode mapping and Playwright worker limit.
Complete runs clean up older tests and databases before starting. Thanks to xet7. Every EVERYTHING run now owns a repository-local process lock. Starting another one first stops the older run and all descendants, frees and verifies ports 3000 and 3001, and removes tagged Playwright and database-conformance containers. Ctrl-C uses the same cleanup for the interrupted run. Cleanup tries graceful termination before a bounded forced stop; if a process, port or container still survives, the replacement exits with an actionable error before creating logs, building WeKan or starting any new tests. PID start tokens prevent stale lock files from targeting an unrelated reused PID on Linux, macOS and Windows.
Sandbox tasks install version-matched local tools under .tools. Thanks to xet7. The agent instructions now treat the repository-local, ignored `.tools` tree as the installation root when the Flatpak sandbox lacks a required command. Node.js and npm versions are read from `Dockerfile`, Meteor from `.meteor/release`, and other tools from their repository-owned version sources instead of stale copied examples. The instructions link the tested sandbox bootstrap, keep environment overrides scoped, and document a local RapidOCR virtual environment for reading timestamped screenshots when bubblewrap prevents the normal image viewer from creating a user namespace.
The complete test matrix cannot create an unbounded shell or Go compiler load. Thanks to xet7. Fedora screenshots showed available memory falling from 28.6 GiB to 371 MiB while the CPU-exec negative regression created a large group of short-lived `bash` processes. The test now captures stdout and stderr from one direct helper invocation instead of launching a duplicate nested shell. The following FerretDB stages limit Go package compilation to two through four workers with a separate managed-heap target, and conformance no longer downloads the root, integration and tools module graphs before building its single binary. Focused positive and negative regressions pin these resource boundaries.
Test runtimes cannot consume the build tool's half-of-RAM heap allowance. Thanks to xet7. The adaptive 8-16 GiB heap ceiling needed while Meteor compiles WeKan was also inherited by the long-lived bundle server and every Node, E2E and Playwright process. A leaking test could therefore consume nearly all workstation RAM and swap before Linux killed it. Runtime processes now use a separate quarter-RAM allowance clamped to 2-4 GiB, while Meteor compilation retains the larger heap. `WEKAN_TEST_NODE_OPTIONS` provides a test-only override. Regression coverage pins both the bounded processes and the deliberately unbounded compiler.
Build and release scripts detect and support Fedora hosts. Thanks to xet7. Host-side dependency installers now choose Fedora's `dnf` commands and package names, including Fedora 44's `7zip`, `gcc-c++`, `glibc-langpack-en` and snapd socket setup. Debian/Ubuntu continue to use apt and macOS continues to use Homebrew. Mocked installer-path tests cover both Fedora and Debian selection.
Installers support Alpine, Arch, RHEL and Oracle Linux. Thanks to xet7. Host-facing shell installers now identify Linux families through `/etc/os-release` and select `apk`, `pacman`, `dnf`, `yum` or `apt-get` with each distribution's package names. Shared compiler and archive setup covers bundle conversion, docs, Sandstorm, release downloads, Snap prerequisites and forge tooling. Alpine and Arch report the manual Snap prerequisite instead of incorrectly running apt. RHEL and Oracle Linux configure their respective EPEL repositories before installing [snapd](https://github.com/wekan/wekan/commit/6d6c574cd). Mocked detection tests cover Alpine, Arch, Fedora, RHEL, Oracle Linux and Debian, and every migrated script is syntax-checked.
Build and release scripts work when launched from macOS zsh. Thanks to xet7. Host-facing Bash scripts now hand direct zsh invocation to macOS's system Bash before parsing Bash-specific syntax. The shared installer detects Darwin without depending on the caller's shell and maps command names to the correct Homebrew formulae for Python, GNU awk, GCC, 7-Zip and Node.js. Regression tests cover the handoff, Darwin detection and every differing formula name.
Scripts keep website and log directories under .tools. Thanks to xet7. Shell and Windows batch scripts now use `.tools/wekan.fi` for the website companion checkout and `.tools/log` for build and test output. This removes the legacy sibling `../w/wekan.fi` and parent `../log` assumptions while preserving the CI environment-variable overrides.
Test runs use the Node and Meteor installations under .tools. Thanks to xet7. A fresh shell did not include `.tools/.meteor` on `PATH`, so EVERYTHING stopped before building with `meteor: command not found` even though setup had installed the exact release there. `build.sh` now prefers the repository-local Meteor and the Node version and architecture named by the release configuration. The companion [FerretDB test runner](https://github.com/wekan/FerretDB/commit/17bb70eb) also generates current version metadata before unit packages initialize and writes standalone logs under `.tools/log`. Its unit, vet and SQLite integration stages pass together.

Thanks to above GitHub users for their contributions and translators for their translations.

Source: README.md, updated 2026-08-22