Binaries in these bundles
Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.
| Bundle | Binary | From | Version | Checked | SHA256 |
|---|---|---|---|---|---|
| amd64 | FerretDB | wekan/FerretDB | v1.63.0 | verified | c9570b1b849d5066… |
| amd64 | Node.js | nodejs.org | v24.20.0 | verified | 2f2c0da162318f0d… |
| arm64 | FerretDB | wekan/FerretDB | v1.63.0 | verified | 019d60c6d2bcee74… |
| arm64 | Node.js | nodejs.org | v24.20.0 | verified | 5f4ddab610c1ab20… |
| armhf | FerretDB | wekan/FerretDB | v1.63.0 | verified | c1bad8f4e7f25f9b… |
| armhf | Node.js | wekan/node-patches | v24.20.0 | verified | b8ed7065d44f0afe… |
| armv6 | FerretDB | wekan/FerretDB | v1.63.0 | verified | 136db594daa70e2c… |
| armv6 | Node.js | wekan/node-patches | v24.20.0 | verified | d5cefa6f8cc4acb1… |
| armv7 | FerretDB | wekan/FerretDB | v1.63.0 | verified | c1bad8f4e7f25f9b… |
| armv7 | Node.js | wekan/node-patches | v24.20.0 | verified | c04c81e539347f39… |
| i386 | FerretDB | wekan/FerretDB | v1.63.0 | verified | 97053d14788ed4e3… |
| i386 | Node.js | wekan/node-patches | v24.20.0 | verified | bb44927307460dcf… |
| mac-arm64 | FerretDB | wekan/FerretDB | v1.63.0 | verified | a2b66ee8a97c8143… |
| mac-arm64 | Node.js | nodejs.org | v24.20.0 | verified | b7bf7707070b950b… |
| mac-x64 | FerretDB | wekan/FerretDB | v1.63.0 | verified | 97d3963b4dc30ef9… |
| mac-x64 | Node.js | nodejs.org | v24.20.0 | verified | 26fc30891004603d… |
| ppc64le | FerretDB | wekan/FerretDB | v1.63.0 | verified | ba5550302c335b1a… |
| ppc64le | Node.js | nodejs.org | v24.20.0 | verified | 341307dcee20d883… |
| s390x | FerretDB | wekan/FerretDB | v1.63.0 | verified | 5cd8100052c464d9… |
| s390x | Node.js | nodejs.org | v24.20.0 | verified | ca381121cb5a8d38… |
| win-arm64 | FerretDB | wekan/FerretDB | v1.63.0 | verified | d931ecbc30b8aac5… |
| win-arm64 | Node.js | nodejs.org | v24.20.0 | verified | 31c6799744de8a54… |
| win64 | FerretDB | wekan/FerretDB | v1.63.0 | verified | 0439d99053a12151… |
| win64 | Node.js | nodejs.org | v24.20.0 | verified | 6cac9ffbca8f6a47… |
A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.
v11.22 2026-08-29 WeKan ® release
In short: RuleBleed closes the server-side automation path that could write cards into an inaccessible private board. Its browser regression now uses isolated rule data so repeated and interrupted test runs remain deterministic.
| Platform | Binary | From | Version | SHA256 |
|---|---|---|---|---|
| amd64 | Node.js | nodejs.org | v24.19.0 | 14b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647 |
| amd64 | FerretDB | wekan/FerretDB | v1.53.0 | eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d |
| arm64 | Node.js | nodejs.org | v24.19.0 | 01443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc |
| arm64 | FerretDB | wekan/FerretDB | v1.53.0 | bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da |
| mac-arm64 | Node.js | nodejs.org | v24.19.0 | 3f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94 |
| mac-arm64 | FerretDB | wekan/FerretDB | v1.53.0 | cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e |
| mac-x64 | Node.js | nodejs.org | v24.19.0 | d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4 |
| mac-x64 | FerretDB | wekan/FerretDB | v1.53.0 | d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3 |
This release fixes the following CRITICAL SECURITY ISSUE of RuleBleed:
Rules cannot write cards into inaccessible private boards. Thanks to crypto-nidh and xet7.
[GHSA-9w4x-hf2r-hc9v](https://github.com/wekan/wekan/security/advisories/GHSA-9w4x-hf2r-hc9v), High, CWE-862 and CWE-863. Move, link and bulk-move automation actions execute server-side, so they bypass the collection deny hook that protects direct DDP writes. Rule creation now validates destination write access before inserting anything, and execution validates again before resolving destination structure. This protects legacy, imported and scheduled rules while removing the private list/swimlane oracle. Denied attempts are bounded and summarized as RuleBleed in Admin Panel → Problems. Positive, negative, legacy-path, REST-preservation and rendered-browser regressions cover both authorization layers.and fixes the following test isolation bug:
Rule authorization checks use isolated browser data. Thanks to xet7.
The RuleBleed browser regression correctly received `not-authorized`, but its global count by a non-unique title found a stale rule left by an earlier interrupted run. The assertion now scopes its query to the current fixture board. Board cleanup also removes its rules, triggers and actions, so one browser project cannot contaminate the next. A source regression pins all three cleanup paths.Thanks to above GitHub users for their contributions and translators for their translations.