NocoBase
NocoBase adds an AI knowledge base retrieval API, connecting no-code workflows to external knowledge sources.
A side-by-side editorial comparison of Kanboard and Tracecat — release velocity, themes, recent moves, and the top alternatives to consider.
Six straight releases of security hardening, now reaching the API's own response shape
Kanboard is a stable, self-hosted PHP kanban board whose release stream is now almost entirely security work. Version 1.2.54 continues that pattern and pushes it further than most: API procedures no longer return private user fields, and changing a password invalidates every existing session and remember-me token. Feature development is close to dormant; the maintenance effort is going into closing whole categories of vulnerability rather than adding surface.
Tracecat hits 1.0 RC with open-source agent presets, agent-case @mentions, and 20+ new security integrations.
Tracecat is in 1.0 release candidate territory, with RC.1 and RC.2 landing in quick succession. The platform has fundamentally expanded its case management system: agents can now be invoked from case comment @mentions, record their mutations back to cases, and have their runs filtered and linked to specific cases. The MCP catalog, agent presets, and skills were open-sourced in RC.1. The integration catalog grew by 20+ providers in beta.52 — Rippling, Jamf, Microsoft Graph, Databricks, Snowflake, Recorded Future, and others. RC.2 adds SSRF blocking for MCP and LLM requests and AWS role chaining.
Kanboard is a stable, self-hosted PHP kanban board whose release stream is now almost entirely security work. Version 1.2.54 continues that pattern and pushes it further than most: API procedures no longer return private user fields, and changing a password invalidates every existing session and remember-me token. Feature development is close to dormant; the maintenance effort is going into closing whole categories of vulnerability rather than adding surface.
The arc from 1.2.49 through 1.2.54 is a systematic audit that works outward from one surface to the next — LDAP escaping, SSRF, deserialization, CSRF, comment visibility, bulk-operation ownership, and now API response shape and session lifetime. Each release also tightens the deployment story, from trusted-proxy configuration to an nginx config that only lets front controllers execute PHP. New user-facing features arrive rarely and small: opt-in full-text search, RTL support, richer API links.
Expect the audit to keep moving through remaining surfaces, with more permission checks in API procedures and continued PHP-version and base-image maintenance. Nothing in these entries points to a new feature direction.
Tracecat is in 1.0 release candidate territory, with RC.1 and RC.2 landing in quick succession. The platform has fundamentally expanded its case management system: agents can now be invoked from case comment @mentions, record their mutations back to cases, and have their runs filtered and linked to specific cases. The MCP catalog, agent presets, and skills were open-sourced in RC.1. The integration catalog grew by 20+ providers in beta.52 — Rippling, Jamf, Microsoft Graph, Databricks, Snowflake, Recorded Future, and others. RC.2 adds SSRF blocking for MCP and LLM requests and AWS role chaining.
Tracecat is building toward a security automation platform where agents are primary workflow participants, not external integrations. The agent@mention model in case comments, combined with open-sourcing the MCP catalog for community contributions, signals a bet on collaborative human-agent case investigation rather than just automated runbooks. Dropping pydantic-ai in beta.52 in favor of a custom durable runtime reflects a commitment to owning the agent execution stack — the kind of choice that enables the SSRF blocking and error classification work shipping in parallel.
The 1.0 stable release will ship shortly and will lead with the agent-case interaction model as the headline capability. Post-stable, watch for expansion of the open-source MCP catalog driven by community contributions and a push around the enterprise entitlement and SCIM system for larger SOC teams.
Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Kanboard or Tracecat.
NocoBase adds an AI knowledge base retrieval API, connecting no-code workflows to external knowledge sources.
RentRedi embeds AI into its maintenance workflow end-to-end, handling tenant intake and drafting landlord replies.
Camunda 8.10 alpha cycles through broad platform bug fixes while 8.7 gets routine security patches
Asana embeds AI into Slack threads and closes the rich-text gap with Notion
Rize pivots from solo time tracker to agency operations platform with invoicing, profitability reporting, and a ChatGPT integration.
Hive is building shared AI automation infrastructure into the core of its PM platform.
See all Kanboard alternatives → · See all Tracecat alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — open-source — within PM. Tracecat is currently shipping more aggressively (velocity 7.5 vs 2.5), with 2 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Tracecat is currently shipping more aggressively (velocity 7.5 vs 2.5), with 2 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.
Top Kanboard alternatives in PM are ranked by recent ship velocity. Browse the "Kanboard alternatives" section above for the current picks, or visit /alternatives/kanboard for the full list with editorial commentary on each.
Top Tracecat alternatives in PM are ranked by recent ship velocity. Browse the "Tracecat alternatives" section above for the current picks, or visit /alternatives/tracecat for the full list with editorial commentary on each.