Sanity
Sanity's MCP server hits v2.33 with safer publishing guards as Studio bug-fix cadence accelerates
A side-by-side editorial comparison of Slurm and NATS — release velocity, themes, recent moves, and the top alternatives to consider.
Slurm coordinated a 7-CVE security drop across three active branches, including a privilege escalation and SQL injection.
Slurm released coordinated security patches across three active branches (25.05.x, 25.11.x, 26.05.x) fixing 7-8 CVEs per branch: sbcast credential bypass (CVE-2026-65107), slurmstepd stack overflow via SPANK environment variables (CVE-2026-65108), OCI container directory traversal (CVE-2026-65109), heap over-read in forward data RPC (CVE-2026-65138), SQL injection via cluster names in accounting queries (CVE-2026-65139), operator-to-administrator privilege escalation (CVE-2026-65140), and step distribution issues (CVE-2026-65165). The 26.05.3 patch also added support for external nodes in heterogeneous jobs — a meaningful expansion for cloud-burst HPC workflows.
NATS 2.15 introduces a desired-state reconciliation engine for JetStream, making cluster operations safe to run mid-flight.
NATS is in the RC phase for v2.15, which centers on a new desired-state metalayer for JetStream — a reconciliation engine that makes stream and consumer placement changes safe to execute during ongoing operations. Cancelling in-flight scale/move operations, changing replication factors mid-move, and peer-removing are all significantly safer. The parallel v2.14.7 release backports metalayer compatibility and fixes a set of JetStream data races and consumer state bugs identified during 2.15 testing.
Slurm released coordinated security patches across three active branches (25.05.x, 25.11.x, 26.05.x) fixing 7-8 CVEs per branch: sbcast credential bypass (CVE-2026-65107), slurmstepd stack overflow via SPANK environment variables (CVE-2026-65108), OCI container directory traversal (CVE-2026-65109), heap over-read in forward data RPC (CVE-2026-65138), SQL injection via cluster names in accounting queries (CVE-2026-65139), operator-to-administrator privilege escalation (CVE-2026-65140), and step distribution issues (CVE-2026-65165). The 26.05.3 patch also added support for external nodes in heterogeneous jobs — a meaningful expansion for cloud-burst HPC workflows.
Slurm's three-branch maintenance model reflects the reality of HPC deployments: clusters running critical workloads don't upgrade quickly, so SchedMD backports security fixes to older release lines rather than forcing upgrades. The CVE density in this release cycle — particularly the accounting database SQL injection and the privilege escalation — suggests the accounting storage layer is under active security scrutiny. Feature work in 26.05.x continues on external node support and async step improvements.
The accounting database SQL injection (CVE-2026-65139) will likely prompt a broader audit of user-controlled inputs to the accounting storage layer. External hetjob support in 26.05.3 will expand as cloud-burst deployments become more common in AI/HPC workloads.
NATS is in the RC phase for v2.15, which centers on a new desired-state metalayer for JetStream — a reconciliation engine that makes stream and consumer placement changes safe to execute during ongoing operations. Cancelling in-flight scale/move operations, changing replication factors mid-move, and peer-removing are all significantly safer. The parallel v2.14.7 release backports metalayer compatibility and fixes a set of JetStream data races and consumer state bugs identified during 2.15 testing.
The desired-state metalayer is an architectural addition that addresses a real operational risk: JetStream's previous behavior required careful sequencing of cluster topology changes to avoid data loss or inconsistent state. The pattern across recent releases — isolated stream read locks, constant-time removal from service maps, reduced client buffer flushing — shows a systematic performance and correctness pass across JetStream at high scale. NATS is moving toward the safety properties needed for production-critical stateful messaging.
v2.15.0 GA will likely ship within weeks of RC.2. The next cycle will probably extend desired-state semantics to more JetStream operations and potentially introduce observability tooling around reconciliation state, giving operators visibility into in-progress cluster changes.
Other DevOps products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Slurm or NATS.
Sanity's MCP server hits v2.33 with safer publishing guards as Studio bug-fix cadence accelerates
Speakeasy becomes the enterprise control plane for MCP server access and AI tool governance.
Kubernetes v1.37 matures its memory management and scheduling stack for AI/ML workloads.
GitHub Copilot gets cost-aware inference tiers as enterprise AI tooling tightens across the platform.
CodeRabbit pushes upmarket with enterprise APIs, rate controls, and a CLI that reviews remotely
Apache Arrow Rust 60.0.0 ships Parquet page index APIs and removes an ownership bottleneck in the Flight path
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — open-source — within DevOps. NATS is currently shipping more aggressively (velocity 7.5 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. NATS is currently shipping more aggressively (velocity 7.5 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other DevOps products to evaluate alongside.
Top Slurm alternatives in DevOps are ranked by recent ship velocity. Browse the "Slurm alternatives" section above for the current picks, or visit /alternatives/slurm for the full list with editorial commentary on each.
Top NATS alternatives in DevOps are ranked by recent ship velocity. Browse the "NATS alternatives" section above for the current picks, or visit /alternatives/nats for the full list with editorial commentary on each.