v11.16
Binaries in these bundles
Each bundle carries a Node.js, a FerretDB and the MongoDB Database Tools.
Which source has a given CPU varies from release to release - nodejs.org
builds some architectures, unofficial-builds others, and the
wekan/node-patches build the ones
neither of them does - and not every source publishes a checksum. This is
what went into this release, and which downloads were checked against a
published SHA256.
| Bundle | Binary | From | Version | Checked | SHA256 |
|---|---|---|---|---|---|
| amd64 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 42b6031e48a6a44c… |
| amd64 | Node.js | nodejs.org | v24.20.0 | verified | 2f2c0da162318f0d… |
| arm64 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 930b33cbc83b35cb… |
| arm64 | Node.js | nodejs.org | v24.20.0 | verified | 5f4ddab610c1ab20… |
| armhf | FerretDB | wekan/FerretDB | v1.62.0 | verified | 2963fdfc690f0cca… |
| armhf | Node.js | wekan/node-patches | v24.19.0 | verified | 46509e82e4f08d0d… |
| armv6 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 58f2f6ddff05b951… |
| armv6 | Node.js | wekan/node-patches | v24.19.0 | verified | 1a76291e8edfd5c0… |
| armv7 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 2963fdfc690f0cca… |
| armv7 | Node.js | wekan/node-patches | v24.19.0 | verified | 1303fbc89fb187c1… |
| i386 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 96919f54f4dabb29… |
| i386 | Node.js | wekan/node-patches | v24.19.0 | verified | c94bc7fc2713b22c… |
| mac-arm64 | FerretDB | wekan/FerretDB | v1.62.0 | verified | af5707904580f34f… |
| mac-arm64 | Node.js | nodejs.org | v24.20.0 | verified | b7bf7707070b950b… |
| mac-x64 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 57dc580ad9b7a8bf… |
| mac-x64 | Node.js | nodejs.org | v24.20.0 | verified | 26fc30891004603d… |
| ppc64le | FerretDB | wekan/FerretDB | v1.62.0 | verified | c93d394f1ce56534… |
| ppc64le | Node.js | nodejs.org | v24.20.0 | verified | 341307dcee20d883… |
| riscv64 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 404bee52f8bb86fa… |
| riscv64 | Node.js | unofficial-builds.nodejs.org | v24.20.0 | verified | a149c5bf85f98ff1… |
| s390x | FerretDB | wekan/FerretDB | v1.62.0 | verified | 7edbadece06a4921… |
| s390x | Node.js | nodejs.org | v24.20.0 | verified | ca381121cb5a8d38… |
| win-arm64 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 9318c87775c42b41… |
| win-arm64 | Node.js | nodejs.org | v24.20.0 | verified | 31c6799744de8a54… |
| win64 | FerretDB | wekan/FerretDB | v1.62.0 | verified | 25fec66a71c9fe50… |
| win64 | Node.js | nodejs.org | v24.20.0 | verified | 6cac9ffbca8f6a47… |
A row saying no checksum published is not a failed check - it is a
source that publishes nothing to check against. Those are the ones worth
fixing at the source.
v11.16 2026-08-27 WeKan ® release
In short: Search pagination now binds every stored query to its
authenticated owner, closing cross-board card disclosure through reused session
IDs. The full release now publishes AppImages automatically after
its core bundles, while 32-bit AppImages distinguish an unavailable runner
from a broken package and keep i686 Node within its virtual-address-space limit.
Card details regain their inner gutters, including on widened desktop panels.
The table below is carried over from the release under this one, and is refilled
from each build's provenance.tsv when this release is made.
| Platform | Binary | From | Version | SHA256 |
|---|---|---|---|---|
| amd64 | Node.js | nodejs.org | v24.19.0 | 14b342e71204f811bde6153be8e04b62aef63c236fef92b55f9c83154b409647 |
| amd64 | FerretDB | wekan/FerretDB | v1.53.0 | eae1f0a8f73bfc979738bfff7284d40fd1bc55de2cc56514721fc155c3624f7d |
| arm64 | Node.js | nodejs.org | v24.19.0 | 01443c1e1a29e531ccad5a46fefa6df490d2189c49f7955904aecdbb0fe86fdc |
| arm64 | FerretDB | wekan/FerretDB | v1.53.0 | bdc50caee3ac28495b42d2130b94a042a9dd6d3a38f732cac02b648f36c891da |
| mac-arm64 | Node.js | nodejs.org | v24.19.0 | 3f1cf157479c1480352083105e13faf9d008ede98e7e157746b6df940d197b94 |
| mac-arm64 | FerretDB | wekan/FerretDB | v1.53.0 | cb14ffe93e285903e5a8a9c1821687ddb5b8a979a11c584bf4af534b272c6d3e |
| mac-x64 | Node.js | nodejs.org | v24.19.0 | d35e95230f46f6f0751df497c56622c6735e05d5e1fb1630996a005b9d328fe4 |
| mac-x64 | FerretDB | wekan/FerretDB | v1.53.0 | d97dfa9afa60aa05f25384327de82efe7b71d958ed24c1f66618284294a65cd3 |
This release fixes the following CRITICAL SECURITY ISSUE of
SessionBleed:
Search pagination sessions cannot be reused across users. Thanks to crypto-nidh and xet7.
The nextPage and previousPage DDP publications accepted a client-supplied
global-search session ID, loaded its stored board selector without checking its
owner, and could return private card titles, descriptions and custom-field
values to a logged-out or different user. The session ID had to be obtained
first, but neither publication enforced the authentication boundary.
Both paths now refuse logged-out clients and perform one owner-scoped lookup
using the authenticated user and session ID together. Missing or foreign
sessions complete without publishing data. Attributable logged-out probes are
folded into a bounded SessionBleed summary in Admin Panel → Problems; ordinary
authenticated pagination is never logged. Positive decision tests, a negative
whole-publication scan and a live Chromium DDP test cover the boundary.
and fixes the following bugs:
AppImage packaging - 32-bit images start safely and report runner limits.
The 32-bit AppImages pass the right startup checks. Thanks to xet7.
The i686 launcher no longer gives a 32-bit Node process a 4 GiB V8 heap that
exhausts its virtual address space while deserializing the startup snapshot.
Automatic selection is capped at 1 GiB for an ELF 32-bit Node, while an explicit
NODE_OPTIONS remains authoritative.
The armhf workflow now probes the Node binary inside the image instead of only
the outer AppImage runtime. A runner whose kernel can execute the wrapper but
lacks /lib/ld-linux-armhf.so.3 therefore uploads the package with an honest
unchecked warning; a runnable Node must still pass the real HTTP smoke test.
Positive and negative plain-Node coverage pins the heap ceiling, override,
inner-runtime probe and smoke-test ordering.
Rebuilt 32-bit AppImages also protect older release bundles. Thanks to xet7.
The v11.15 rerun proved that fixing the bundle launcher alone was insufficient:
an AppImage wraps the ZIP already attached to that release, so its bundled
start-wekan.sh still predated the fix and i686 again died with GC during deserialization.
The generated AppRun now supplies the same 1 GiB V8 ceiling for i686 and armhf
before invoking the bundle launcher. This makes a missing AppImage safely
rebuildable around an older published ZIP, while ${NODE_OPTIONS} supplied by
an administrator still wins. Regression coverage pins that old-bundle boundary
and the architecture substitution.
The full release publishes its AppImages automatically. Thanks to xet7.
release-all.yml built and published the core ZIP bundles but never called the
reusable AppImage workflow, leaving AppImages to a separate manual or
missing-assets run. It now calls AppImage.yml immediately after the core
GitHub Release has attached its amd64 and arm64 ZIPs. The exact new tag is
passed explicitly, release-asset write permission is scoped to the call, and
the work runs in parallel with the other post-release formats.
Regression coverage pins the release dependency, reusable-workflow path, tag,
publish flag and permission, while the workflow-interface guard proves the
called workflow exists and accepts every supplied input.
Card details - visible content stays inset at standard and custom widths.
Opened cards apply their side gutters to the visible content. Thanks to rmb82 and xet7.
An accessibility markup change accidentally made .card-details-canvas an
empty sibling of the card header and body. Its computed 20-pixel padding still
looked correct, but no visible content was inside it, so descriptions and custom
fields touched the panel edges.
The canvas once again owns the whole card body. Positive and negative source
coverage pins that ownership and rejects the empty-sibling structure, while the
Playwright regression reproduces an 1100-pixel desktop panel and verifies the
actual content-to-edge gaps rather than trusting the wrapper's computed style.
Thanks to above GitHub users for their contributions and translators for their translations.