SiYuan
SiYuan v3.8.4 beta cycle adds agent-controlled database fields, MiniMax image gen, and skill file management
A side-by-side editorial comparison of CommaFeed and Wiki.js — release velocity, themes, recent moves, and the top alternatives to consider.
CommaFeed's security pass turns inward, from hostile feeds to hostile users
CommaFeed's 7.x line has become a sustained security pass, shipped one fix per patch release. The newest, 7.3.2, closes a cross-user data exposure: users could star or tag entries that were not theirs and then read them, filed as GHSA-prfv-88mm-5gpg. Behind it sit Host header injection on the password recovery endpoint with a new commafeed.password-recovery-public-base-url setting, local address blocking made secure by default alongside Google Reader API support in 7.3.0, and javascript: URL filtering moved to parse time.
Wiki.js 3.0 beta closes enterprise auth and SEO gaps at sprint pace
Wiki.js is running a dual-track strategy: v2.5.x is in maintenance, collecting only security and bug fixes, while v3.0.0 moves through beta weekly with substantial new features. The v3 beta has concentrated recent drops on two converging pillars — enterprise authentication (Entra ID, LDAP, SAML, Discord with group-to-role mapping) and operations infrastructure (Audit Log, admin metrics, sitemap serving, prerendering for anonymous requests). All active development runs through a single committer, shipping multiple named features per weekly beta build.
CommaFeed's 7.x line has become a sustained security pass, shipped one fix per patch release. The newest, 7.3.2, closes a cross-user data exposure: users could star or tag entries that were not theirs and then read them, filed as GHSA-prfv-88mm-5gpg. Behind it sit Host header injection on the password recovery endpoint with a new commafeed.password-recovery-public-base-url setting, local address blocking made secure by default alongside Google Reader API support in 7.3.0, and javascript: URL filtering moved to parse time.
The earlier fixes in this run all closed paths where something from outside the instance was trusted too far — feed URLs reaching internal addresses, proxied images, javascript: links, a request header shaping an outbound email. 7.3.2 is a different shape: nothing external is involved, the attacker is a legitimate signed-in user, and the flaw is an ownership check missing on a write path that then leaks through a read path. That is the class of bug you find once you start auditing multi-tenancy rather than input handling, and it suggests the review has moved past the perimeter into the authorization model that the 7.0.0 multi-user rework put in place.
If the audit is now working through ownership checks rather than input validation, the other per-user write paths — subscription and category mutations, saved searches — are the likely next findings. The pattern of shipping each fix as its own patch release with a GHSA reference should continue rather than batching them.
Wiki.js is running a dual-track strategy: v2.5.x is in maintenance, collecting only security and bug fixes, while v3.0.0 moves through beta weekly with substantial new features. The v3 beta has concentrated recent drops on two converging pillars — enterprise authentication (Entra ID, LDAP, SAML, Discord with group-to-role mapping) and operations infrastructure (Audit Log, admin metrics, sitemap serving, prerendering for anonymous requests). All active development runs through a single committer, shipping multiple named features per weekly beta build.
The v3 beta is systematically filling the gaps that have kept Wiki.js out of enterprise environments: SSO across major identity providers, compliance tooling, SEO readiness, and theme customization for whitelabeled deployments. Each week's build adds a category that a production deployment actually requires. The remaining areas not yet visible in the beta changelog are storage/sync providers and full editor-module parity with v2 — those gaps are the logical preconditions for an RC.
The next beta cycle will likely address storage backends and remaining editor modules. A release candidate becomes the natural next step once those surface areas are covered.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either CommaFeed or Wiki.js.
SiYuan v3.8.4 beta cycle adds agent-controlled database fields, MiniMax image gen, and skill file management
GitHub Copilot gets cost-aware inference tiers as enterprise AI tooling tightens across the platform.
Nextcloud runs three LTS branches in parallel, shipping bug fixes and quiet performance wins.
Mattermost builds out its thought-leadership case for regulated-industry AI while v12.0 deprecations signal a platform break
Teable adds Composio integration and Scheduled Routines, pivoting from spreadsheet to agentic workflow platform.
Happeo doubles down on SEO content to own intranet search terms for mid-market buyers.
See all CommaFeed alternatives → · See all Wiki.js alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted — within Collab. Wiki.js is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Wiki.js is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top CommaFeed alternatives in Collab are ranked by recent ship velocity. Browse the "CommaFeed alternatives" section above for the current picks, or visit /alternatives/commafeed for the full list with editorial commentary on each.
Top Wiki.js alternatives in Collab are ranked by recent ship velocity. Browse the "Wiki.js alternatives" section above for the current picks, or visit /alternatives/wiki-js for the full list with editorial commentary on each.