Download Latest Version wekan-11.72-s390x.zip (286.8 MB)
Email in envelope

Get an email when there's a new version of wekan

Home / v11.55
Name Modified Size InfoDownloads / Week
Parent folder
wekan_11.55_ppc64el.snap 2026-09-07 305.8 MB
wekan_11.55_armhf.snap 2026-09-07 288.9 MB
wekan_11.55_s390x.snap 2026-09-07 304.9 MB
wekan_11.55_arm64.snap 2026-09-07 460.0 MB
wekan_11.55_amd64.snap 2026-09-07 568.7 MB
WeKan-11.55-x86_64.AppImage.md5sum 2026-09-07 62 Bytes
WeKan-11.55-x86_64.AppImage.sha256sum 2026-09-07 94 Bytes
WeKan-11.55-armhf.AppImage.sha256sum 2026-09-07 93 Bytes
WeKan-11.55-i686.AppImage 2026-09-07 214.7 MB
WeKan-11.55-i686.AppImage.md5sum 2026-09-07 60 Bytes
WeKan-11.55-i686.AppImage.sha256sum 2026-09-07 92 Bytes
WeKan-11.55-x86_64.AppImage 2026-09-07 219.6 MB
WeKan-11.55-aarch64.AppImage 2026-09-07 215.5 MB
WeKan-11.55-aarch64.AppImage.md5sum 2026-09-07 63 Bytes
WeKan-11.55-aarch64.AppImage.sha256sum 2026-09-07 95 Bytes
WeKan-11.55-armhf.AppImage 2026-09-07 208.0 MB
WeKan-11.55-armhf.AppImage.md5sum 2026-09-07 61 Bytes
wekan-11.55-sandstorm.spk 2026-09-07 166.8 MB
wekan-11.55-ppc64le.zip 2026-09-07 270.1 MB
wekan-11.55-ppc64le.zip.sha256sum 2026-09-07 90 Bytes
wekan-11.55-win64.zip 2026-09-07 252.1 MB
wekan-11.55-win64.zip.sha256sum 2026-09-07 88 Bytes
wekan-11.55-riscv64.zip 2026-09-07 269.0 MB
wekan-11.55-riscv64.zip.sha256sum 2026-09-07 90 Bytes
wekan-11.55-s390x.zip 2026-09-07 271.5 MB
wekan-11.55-s390x.zip.sha256sum 2026-09-07 88 Bytes
wekan-11.55-armhf.zip 2026-09-07 256.4 MB
wekan-11.55-armhf.zip.sha256sum 2026-09-07 88 Bytes
wekan-11.55-armv6.zip 2026-09-07 257.3 MB
wekan-11.55-armv6.zip.sha256sum 2026-09-07 88 Bytes
wekan-11.55-mac-arm64.zip 2026-09-07 259.9 MB
wekan-11.55-mac-arm64.zip.sha256sum 2026-09-07 92 Bytes
wekan-11.55-armv7.zip 2026-09-07 256.4 MB
wekan-11.55-armv7.zip.sha256sum 2026-09-07 88 Bytes
wekan-11.55-win-arm64.zip 2026-09-07 241.3 MB
wekan-11.55-win-arm64.zip.sha256sum 2026-09-07 92 Bytes
wekan-11.55-i386.zip 2026-09-07 262.8 MB
wekan-11.55-i386.zip.sha256sum 2026-09-07 87 Bytes
wekan-11.55-mac-x64.zip 2026-09-07 223.9 MB
wekan-11.55-mac-x64.zip.sha256sum 2026-09-07 90 Bytes
wekan-11.55-amd64.zip 2026-09-07 264.2 MB
wekan-11.55-amd64.zip.sha256sum 2026-09-07 88 Bytes
wekan-11.55-arm64.zip 2026-09-07 264.1 MB
wekan-11.55-arm64.zip.sha256sum 2026-09-07 88 Bytes
README.md 2026-09-07 19.1 kB
v11.55 source code.tar.gz 2026-09-07 43.3 MB
v11.55 source code.zip 2026-09-07 45.1 MB
Totals: 47 Items   6.4 GB 0

Binaries in these bundles

Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools. Which source has a given CPU varies from release to release - nodejs.org builds some architectures, unofficial-builds others, and the wekan/node-patches build the ones neither of them does - and not every source publishes a checksum. This is what went into this release, and which downloads were checked against a published SHA256.

Bundle Binary From Version Checked SHA256
amd64 FerretDB wekan/FerretDB v1.71.0 verified 588b81faa6049d3b…
amd64 Node.js nodejs.org v24.20.0 verified 2f2c0da162318f0d…
arm64 FerretDB wekan/FerretDB v1.71.0 verified 34b0858526c9aa1a…
arm64 Node.js nodejs.org v24.20.0 verified 5f4ddab610c1ab20…
armhf FerretDB wekan/FerretDB v1.71.0 verified 1597842dbad151bd…
armhf Node.js wekan/node-patches v24.20.0 verified b8ed7065d44f0afe…
armv6 FerretDB wekan/FerretDB v1.71.0 verified a98992a211d1302d…
armv6 Node.js wekan/node-patches v24.20.0 verified d5cefa6f8cc4acb1…
armv7 FerretDB wekan/FerretDB v1.71.0 verified 1597842dbad151bd…
armv7 Node.js wekan/node-patches v24.20.0 verified c04c81e539347f39…
i386 FerretDB wekan/FerretDB v1.71.0 verified f3bc7e4c915e10c6…
i386 Node.js wekan/node-patches v24.20.0 verified bb44927307460dcf…
mac-arm64 FerretDB wekan/FerretDB v1.71.0 verified d10ab602d8299655…
mac-arm64 Node.js nodejs.org v24.20.0 verified b7bf7707070b950b…
mac-x64 FerretDB wekan/FerretDB v1.71.0 verified 8cbb7d2957be662d…
mac-x64 Node.js nodejs.org v24.20.0 verified 26fc30891004603d…
ppc64le FerretDB wekan/FerretDB v1.71.0 verified e96028e8886454a3…
ppc64le Node.js nodejs.org v24.20.0 verified 341307dcee20d883…
riscv64 FerretDB wekan/FerretDB v1.71.0 verified b391572ddd1b3f60…
riscv64 Node.js unofficial-builds.nodejs.org v24.20.0 verified a149c5bf85f98ff1…
s390x FerretDB wekan/FerretDB v1.71.0 verified 8d4d865a3447524f…
s390x Node.js nodejs.org v24.20.0 verified ca381121cb5a8d38…
win-arm64 FerretDB wekan/FerretDB v1.71.0 verified 0b73fa1b2c87f5a0…
win-arm64 Node.js nodejs.org v24.20.0 verified 31c6799744de8a54…
win64 FerretDB wekan/FerretDB v1.71.0 verified bf5a6581d2218623…
win64 Node.js nodejs.org v24.20.0 verified 6cac9ffbca8f6a47…

A row saying no checksum published is not a failed check - it is a source that publishes nothing to check against. Those are the ones worth fixing at the source.

v11.55 2026-09-07 WeKan ® release

In short: Legacy HTML4 is reverted, restoring the standard Meteor browser interface. Local branding images, searchable document previews, browser lazy loading, translation updates and the session-upgrade fix remain. Meteor tests compile, and authentication forms follow keyboard order. Swimlane and card controls regain their previous colors, and upgraded sessions retain their profile without a duplicate login.

Platform Binary From Version SHA256
amd64 Node.js nodejs.org v24.19.0 14b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647
amd64 FerretDB wekan/FerretDB v1.53.0 eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d
arm64 Node.js nodejs.org v24.19.0 01443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc
arm64 FerretDB wekan/FerretDB v1.53.0 bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da
mac-arm64 Node.js nodejs.org v24.19.0 3f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94
mac-arm64 FerretDB wekan/FerretDB v1.53.0 cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e
mac-x64 Node.js nodejs.org v24.19.0 d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4
mac-x64 FerretDB wekan/FerretDB v1.53.0 d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3

This release reverts Legacy HTML4 and retains the following changes:

Browser interface - standard Meteor pages and deferred browser code.

Restore independent swimlane and card control colors. Thanks to Alishara and xet7. Revert the client styling from the swimlane title-color matching change and the card title-color matching change. Swimlane controls again use neutral gray and darker hover colors, and card controls regain their previous styling. Remove the shared card-control class and the added light-card title overrides. Updated source guards cover the restored colors and retained card palette. Four live checks in Chromium and Firefox verify swimlane normal/hover colors and card controls on colored backgrounds at [testi.wekan.fi](https://testi.wekan.fi).
Keep upgraded session profiles without a duplicate login. Thanks to Alishara and xet7. The earlier session-upgrade repair repeated a token login that Accounts had already started. Live DDP diagnostics reproduced the remaining symptoms of [#6677](https://github.com/wekan/wekan/issues/6677): the user ID remained logged in, but rebuilding subscriptions cleared the published profile. The saved profile in the database was unchanged. This is separate from control CSS. Move the existing credential and expiry into Accounts' memory store, remove its old persistent copy, synchronize the token poll and let the native validated endpoint set the HttpOnly cookie. Do not repeat the initial login. Cookie-only clients continue using the native cookie resume. Unit scenarios cover completed and pending initial logins and cookie-only startup. The extended live regression checks the name, loaded avatar and theme past the three-second poll, edits the name and theme, favorites the board, switches to list view and verifies persistence after a cookie-only reload. Both Chromium and Firefox pass this regression and the private-board refresh check. Native Edge, AD authentication and WebKit were not exercised. The Upcoming coverage audit ran all Node suites: 858 checks passed, with the same two pre-existing failures for an undocumented test-results directory and Finnish rule-description wording. All three targeted color/session suites pass.
Revert Legacy HTML4. Thanks to xet7. Remove the Legacy HTML4 and Legacy Omi progressive browser interface, its cookieless sessions, page controllers, assets and parity refactors. Page requests again use the standard Meteor interface and the previous browser operations. The HTML4 design documents, paused-work backlog and feature tests are removed. Intervening translation updates, backup screenshots, session-upgrade repairs, cryptographic test identifiers, local image storage, searchable document previews and browser lazy loading remain. Shared GIF utilities now live in an independent image module so the retained image features have no HTML4 dependency. The Node suite run and targeted reruns pass apart from two failures reproduced with the previous code: an undocumented existing test-results directory and a Finnish rule-description expectation. Five new interface and image checks pass; 121 changed application modules parse and their 1,001 local imports resolve. Live validation at [testi.wekan.fi](https://testi.wekan.fi) passes eight checks in Chromium and Firefox: standard sign-in, JavaScript-disabled responses, member board loading and non-member denial. WebKit cannot launch with the available system libraries. Existing suites cover the retained Upcoming features, session repair, build fix, keyboard navigation and email documentation.
Lazy-load browser export code and share its ZIP implementation. Thanks to xet7. HTML export and its ZIP writer now load only after the HTML Export action is clicked. The direct JSZip dependency is removed; export uses the same small MIT `fflate` implementation as server-side document conversion, while ZIP imports continue through the bounded streaming server route. Gantt no longer imports an unused Markdown parser, and attachment UI no longer loads BSON merely to create or display an identifier. Tests keep the feature boundary dynamic, prevent the duplicate ZIP library from returning, and cover the import/export paths.
Share the streaming ZIP reader with Trello imports. Thanks to xet7. Trello package import no longer relies on an undeclared JSZip copy. It uses the same server-side `unzipper` reader as the bounded backup and scoped-import paths, while retaining path, entry-count, expanded-size and per-file limits. This leaves `fflate` as the small lazy browser/document ZIP implementation and `unzipper` as the server reader for large streamed input.

Sign in and sign up - keyboard order and session continuity.

Keep profiles and preferences through session upgrades. Thanks to Alishara and xet7. Upgrading from v11.39 no longer replaces the browser's existing resume-token store before that token has migrated to the new HttpOnly cookie flow. The three-second Accounts token poll therefore cannot log out the restored user and remove their reactive name, avatar, theme, favorites and board-view settings. Static positive and negative coverage pins the migration order and forbids direct token writes. A Chromium regression recreates the old local-token state, checks the profile and board view, and remains logged in beyond the poll window.
Fix authentication form keyboard navigation. Thanks to xet7. Tab now moves directly from each sign-in or sign-up writing field to the next one below it without stopping on a show/hide-password control. The controls remain available by pointer and assistive technology. Native Enter submission remains active in the bottom field. Source and three-browser tests cover the positive field order, the skipped controls, failed-login submission and successful account creation.

Images and attachments - local images and searchable document previews.

Store searchable document text and GIF attachment previews. Thanks to xet7. PDF, DOCX, XLSX and PPTX previews are now generated on the server and cached in Default Storage. Plain Unicode text is stored without formatting in a separate unpublished `searchText` field, displayed as selectable text, and exposed to a board-authorized attachment-text search method. Embedded document images and PDF page imagery are converted to GIF; page controls browse the combined lightweight representation. Source bytes, decoded text, page count, archive entries and expanded OOXML data are all bounded. ZIP entries are streamed, malformed images do not suppress readable text, generated data is tied to the original checksum, and every manifest, image and search request repeats board-read authorization. The small conversion stack is MIT and Apache-2.0 only; no GPL, LibreOffice, Ghostscript, browser runtime or OCR dependency is added. Tests cover the storage split, authorization, regex escaping, selectable safe rendering, GIF routes, size limits, licenses and vulnerable-version exclusions. Sharp is updated to 0.35.4 so untrusted image decoding also receives the current libvips security fixes.
Store branding and board background images locally as GIF. Thanks to xet7. Admin Panel instance and Organization branding now offers image upload controls instead of editable external image URL fields. Every upload is authorized, bounded, decoded and converted to GIF on the server before it is written to Admin Panel / Attachments / Default Storage. Direct REST and tenant-setting writes cannot restore an arbitrary image source URL. The separately configured logo click destination is unchanged. At startup, existing external login logos, header logos and board backgrounds are downloaded through the SSRF-safe fetcher, converted to GIF and atomically replaced with internal URLs. A failed legacy download is removed immediately from client- visible data and retained only in an unpublished retry queue for the next startup. Board Settings likewise offers only upload, unset and the stored-background list; new board backgrounds pass through a board-admin-checked GIF conversion method. Offline imports no longer activate third-party background URLs. Regression coverage checks authorization, input limits, SSRF-safe migration, Default Storage selection, GIF-only output, response hardening, hidden URL write paths, board-background upload and import behavior.

Tests and build - compilation and secure test identifiers.

Verify the restored browser interface over HTTPS. Thanks to xet7. Playwright readiness selects HTTPS for a public HTTPS test URL. The board non-member regression waits for the rendered denial and absence of the canvas, so the development server's persistent SockJS polling cannot cause a false network-idle timeout. The HTTPS guard and eight live Chromium/Firefox checks pass.
Use cryptographic randomness throughout Playwright tests. Thanks to xet7. All Playwright fixture usernames, addresses, object identifiers and run markers now come from one Node `crypto.randomBytes` helper instead of `Math.random`. This resolves CodeQL alerts 450 through 522 and prevents predictable randomness from becoming normalized in tests that exercise authentication and authorization boundaries. A source regression scans every Playwright helper and specification, requires the shared helper to remain CSPRNG-backed and refuses any executable `Math.random()` call. The retained files pass JavaScript syntax checks; the removed HTML4 browser specifications no longer form part of this coverage.
Fix the Meteor client test bundle. Thanks to xet7. The isomorphic change-history integrity helper now computes synchronous SHA-256 without importing Node `crypto`, so client tests no longer pull in `crypto-browserify` and fail on its unresolved `vm` and `stream` modules. Test vectors compare the implementation with Node's SHA-256, and the compiled client source map is free of the former dependency chain. The language-loading test now checks i18next state without a dynamic `require` warning. Test-run signal handlers disarm themselves before cleanup, preventing repeated Ctrl-C presses from recursively restarting port cleanup.

Documentation - deployment email configuration.

Document Admin Panel email configuration. Thanks to xet7. Snap help, every current Docker Compose example, Unix and Windows start scripts, and the VirtualBox launcher now explain above `MAIL_URL` that enabling **Enable below email settings** at Admin Panel / People / Email reveals the additional email sending options. A regression check keeps that guidance present and in the correct order across every deployment example.

Thanks to above GitHub users for their contributions and translators for their translations.

Source: README.md, updated 2026-09-07