Knock
Knock plants its flag across every major AI platform: Claude, ChatGPT, Codex, and Cursor all get native connectors
A side-by-side editorial comparison of Authelia and Dragonfly — release velocity, themes, recent moves, and the top alternatives to consider.
Authelia patches two access control bypass paths from canonicalization gaps.
Authelia v4.39.x is in a sustained hardening cycle: a critical security release in May fixed two authentication bypass paths, and subsequent patch releases have worked through a dense queue of OIDC protocol compliance bugs — resource indicators, client credentials foreign key handling, authentication strategy configuration, and resource strategy matching. The pace of micro-patches (v4.39.21 through v4.39.25 in a two-week window) reflects active production use surfacing edge cases.
Dragonfly tags v2.0.0 while hardening memory accounting and patching a HyperLogLog CVE across the 1.x line
Dragonfly is shipping across two concurrent tracks: the 1.40.x stable line is receiving steady improvements to connection memory accounting correctness, tiering metrics, and Redis ecosystem compatibility (RedisShake RDB format), while v2.0.0 has been tagged. The 2.0.0 entry's visible content is minimal — scope-based memory tracking is added but disabled — suggesting 2.0.0 is an architectural milestone marker for accumulated work rather than a single user-visible feature introduction.
Authelia v4.39.x is in a sustained hardening cycle: a critical security release in May fixed two authentication bypass paths, and subsequent patch releases have worked through a dense queue of OIDC protocol compliance bugs — resource indicators, client credentials foreign key handling, authentication strategy configuration, and resource strategy matching. The pace of micro-patches (v4.39.21 through v4.39.25 in a two-week window) reflects active production use surfacing edge cases.
The OIDC fix pattern is deliberate: Authelia is closing gaps in the parts of OAuth 2.0/OIDC that enterprise clients actually use — resource indicators, client credentials grants, pooled authentication. This isn't maintenance drift; it's building toward a more complete OIDC server for complex multi-client deployments. The access control canonicalization fix from May signals a broader audit of how Authelia normalizes domain names and usernames before authorization decisions.
The OIDC compliance fixes in v4.39.x are groundwork for new grant types and flows in a future major version. Expect device authorization flow or Pushed Authorization Requests (PAR) to appear in a v4.40 or v5.x roadmap entry once the protocol surface is cleaned up.
Dragonfly is shipping across two concurrent tracks: the 1.40.x stable line is receiving steady improvements to connection memory accounting correctness, tiering metrics, and Redis ecosystem compatibility (RedisShake RDB format), while v2.0.0 has been tagged. The 2.0.0 entry's visible content is minimal — scope-based memory tracking is added but disabled — suggesting 2.0.0 is an architectural milestone marker for accumulated work rather than a single user-visible feature introduction.
The project's operational focus is sharpening around production reliability and Redis compatibility: O(1) connection memory tracking, per-shard tiering metrics, CVE-2025-32023 remediation in HyperLogLog, and AVX2/NEON SIMD acceleration for dense HLL operations (8-29x measured gains). The staged 2.0.0 release and the disabled scope-based memory tracking point to Dragonfly building toward granular per-connection memory visibility as a differentiating feature for operators running large clusters.
Scope-based memory tracking will be re-enabled in a near-term 2.x patch — the code is already shipped in 2.0.0, just gated off. That re-enable will be the actual headline for what 2.0.0 unlocks operationally.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Authelia or Dragonfly.
Knock plants its flag across every major AI platform: Claude, ChatGPT, Codex, and Cursor all get native connectors
Honeybadger pivots from error tracker to full observability layer with AI-native query and anomaly detection
Resend expands from email API to full platform with SSO, analytics, and AI-native dev tooling
Helm 3 ships its final minor release while Helm 4.3 eliminates multi-minute status computation delays.
Quay ships a series of SSRF fixes in mirroring and proxy cache alongside steady CVE patching across 3.10 and 3.12 branches.
Redocly releases daily Reunite builds, hardening AI search RBAC and expanding MCP tool support.
See all Authelia alternatives → · See all Dragonfly alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Dragonfly is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Dragonfly is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Authelia alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Authelia alternatives" section above for the current picks, or visit /alternatives/authelia for the full list with editorial commentary on each.
Top Dragonfly alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Dragonfly alternatives" section above for the current picks, or visit /alternatives/dragonfly for the full list with editorial commentary on each.