Process Street
Process Street's public feed is an SEO content engine, not a changelog.
A side-by-side editorial comparison of ActiveCollab and Wakapi — release velocity, themes, recent moves, and the top alternatives to consider.
AI agents got the keys in June; in July ActiveCollab added the locks.
ActiveCollab ships small, self-contained changes on a roughly weekly cadence, and this window covers three fronts. Security gained an IP allowlist and per-tool permissions for MCP agents, both filed under Security settings. The client layer was rebuilt, with native macOS and Windows desktop apps replacing Electron and distributed through the platform app stores, followed by dark themes that match system appearance. Collaboration picked up chat favorites and self-expiring mute, plus an activity heatmap on My Work.
A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.
Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.
ActiveCollab ships small, self-contained changes on a roughly weekly cadence, and this window covers three fronts. Security gained an IP allowlist and per-tool permissions for MCP agents, both filed under Security settings. The client layer was rebuilt, with native macOS and Windows desktop apps replacing Electron and distributed through the platform app stores, followed by dark themes that match system appearance. Collaboration picked up chat favorites and self-expiring mute, plus an activity heatmap on My Work.
The clearest thread runs through MCP. In mid-June the product made individual comments linkable specifically so an AI agent could retrieve one; four weeks later it shipped controls restricting which MCP tools those agents may call. That is a reach-then-govern sequence, and putting agent permissions in Security settings next to the IP firewall says an agent is being treated as a principal to scope rather than an integration to enable. Everything else in the window is steady quality-of-life and platform hygiene.
Expect the governance layer around MCP to keep filling in - audit logging of agent actions, or per-role rather than per-account tool limits, is the natural next step given both new controls landed in Security settings on the same day.
Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.
The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user are the requirements that come from someone else's security review. The 2.17.6 bypass sits awkwardly against that: a cache keyed without proper namespacing is exactly the class of bug that multi-tenant deployment surfaces, which suggests the auth work is now being exercised harder than the code was written for. Releases have also thinned to roughly one a month from a much faster earlier cadence.
The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.
Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either ActiveCollab or Wakapi.
Process Street's public feed is an SEO content engine, not a changelog.
NocoBase runs two release lines at once while the v3 client rewrite absorbs the AI work
Hive ships in batches, and this one is all planning accuracy and admin control.
Plane ships a fortnightly digest, and the AI layer is where the real work is going.
Ever Teams shipped ten tags in twelve hours and one of them touched the product
Asana's agent left the app — it now answers work questions inside Slack threads.
See all ActiveCollab alternatives → · See all Wakapi alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. ActiveCollab is currently shipping more aggressively (velocity 6.3 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. ActiveCollab is currently shipping more aggressively (velocity 6.3 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.
Top ActiveCollab alternatives in PM are ranked by recent ship velocity. Browse the "ActiveCollab alternatives" section above for the current picks, or visit /alternatives/activecollab for the full list with editorial commentary on each.
Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.