Dashy
The self-hosted dashboard finally let you drag things around instead of editing YAML.
A side-by-side editorial comparison of AdGuard Home and Sonarr — release velocity, themes, recent moves, and the top alternatives to consider.
AdGuard Home is spending most of its release capacity on DNS protocol vulnerabilities.
Two trains run in parallel: the 0.107.x stable line and a long-running 0.108.0 beta series now at b.90. Security dominates both — one stable release opened by admitting security changes take up over half its changelog. The reported issues cluster in the encrypted-DNS stack: JIGGLE attacks, loose validation of DoH upstream responses, unbounded reads on QUIC connections, DNS-over-QUIC resource exhaustion, and a path traversal in GLiNET-mode authorization. Feature work in the window is minor: comments in bootstrap server configuration, removing a static lease hostname via the HTTP API, day units in YAML durations.
Sonarr's release feed is a two-month run of one-line fixes, most of them about qBittorrent auth.
Ten releases in this window, several cut hours apart, and almost every one carries a single change. The dominant thread is download-client authentication: basic auth for qBittorrent, reusing authentication cookies across qBittorrent calls, and backporting both to the v4 line — the same two fixes appearing repeatedly as they propagate across branches. The rest is a Jellyfin and Emby connection test with a new Jellyfin auth header, a language-handling correction, and dependency bumps for MailKit and FFprobe.
Two trains run in parallel: the 0.107.x stable line and a long-running 0.108.0 beta series now at b.90. Security dominates both — one stable release opened by admitting security changes take up over half its changelog. The reported issues cluster in the encrypted-DNS stack: JIGGLE attacks, loose validation of DoH upstream responses, unbounded reads on QUIC connections, DNS-over-QUIC resource exhaustion, and a path traversal in GLiNET-mode authorization. Feature work in the window is minor: comments in bootstrap server configuration, removing a static lease hostname via the HTTP API, day units in YAML durations.
The 0.108 beta has been running long enough that its interesting signal is the edge channel switching to the new UI and versioning scheme — the rewrite is reaching users before the beta closes. Meanwhile the security cadence is community-driven: nearly every fix credits an external reporter, and fixes land in a beta and its stable counterpart within days or the same day. That is a project whose attack surface is its protocol implementations, and whose defence is a fast disclosure-to-patch loop rather than architectural change.
Expect the encrypted-DNS transports to keep generating reports and same-week patches on both branches, and the new UI to widen from the edge channel toward beta as 0.108 approaches release.
Ten releases in this window, several cut hours apart, and almost every one carries a single change. The dominant thread is download-client authentication: basic auth for qBittorrent, reusing authentication cookies across qBittorrent calls, and backporting both to the v4 line — the same two fixes appearing repeatedly as they propagate across branches. The rest is a Jellyfin and Emby connection test with a new Jellyfin auth header, a language-handling correction, and dependency bumps for MailKit and FFprobe.
This is mature-product maintenance, and the failure surface is entirely at the integration boundary — the download clients and media servers Sonarr talks to change their auth behaviour, and Sonarr chases them. Releases are cut per-fix rather than batched, which produces a high tag count from a low volume of actual change. Nothing in this window touches Sonarr's own capability surface.
Expect the same pattern to continue: small single-change releases tracking download-client and media-server API shifts, with no visible feature work on the 4.0 line.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either AdGuard Home or Sonarr.
The self-hosted dashboard finally let you drag things around instead of editing YAML.
The web's duct-tape RSS layer, now quiet for a year after flipping every bridge on by default.
A daily-shipping indexer proxy whose entire product is a scraper definition file that never stops rotting.
k0s ships one fix four times a day — the cost of keeping four Kubernetes branches current.
Microcks is quietly wiring LLM example generation into an API mocking tool built for Kubernetes.
Borg's long-running 2.0 beta finally landed packs — and warned it dropped back to alpha quality.
See all AdGuard Home alternatives → · See all Sonarr alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. AdGuard Home and Sonarr are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. AdGuard Home and Sonarr are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top AdGuard Home alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "AdGuard Home alternatives" section above for the current picks, or visit /alternatives/adguard-home for the full list with editorial commentary on each.
Top Sonarr alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Sonarr alternatives" section above for the current picks, or visit /alternatives/sonarr for the full list with editorial commentary on each.