BookStack vs Jira
Side-by-side trajectory, velocity, and editorial themes.
BookStack opened a real theme extension surface, then spent six weeks patching CVEs.
BookStack shipped v26.03 in mid-March 2026 with a meaningful new theme module system and several theme events (page render, pre-save, OIDC URL customization) — the first time the project's customization surface has had real extension points rather than just template overrides. The next six weeks were almost entirely security work: four security-marked patch releases (v25.12.9, v26.03.1, v26.03.2, v26.03.4) addressing role-escalation via registration, hidden content leaking through markdown exports, style-code injection in revision diffs, and attachment/webhook URL validation gaps. Multiple researchers credited per release.
The arc is 'open up the platform, then defend it' — adding extension points was the v26.03 push, and the subsequent CVE volume reads as a coordinated audit response (often two researchers credited per advisory, suggesting public attention from pen-testers). The 25.12.x line is also still being patched in parallel, indicating the team is supporting both branches rather than forcing rapid upgrades.
Expect another v26.03.x patch release if the audit cycle isn't complete, then a return to feature work — likely more theme-event coverage and exposing more lifecycle hooks to match what the new module system can attach to. The dual-branch maintenance pattern probably continues until v25.12 hits its support cutoff.
Atlassian is quietly turning Jira into the connective tissue for an AI-driven enterprise work platform.
Jira keeps shipping along two tracks at once. One is enterprise lifecycle plumbing — sandbox-to-production config promotion, guest access on paid plans, multi-space service queues — that closes long-standing change-management and collaboration gaps. The other is platform expansion: HRIS data flowing into the Atlassian Teamwork Graph, Rovo skills landing inside Jira Align, and Bitbucket merge queues.
The center of gravity is moving from issue tracking to a unified work platform with AI on top of an enriching Teamwork Graph. Atlassian is treating the Graph as the substrate Rovo reasons over, and is now feeding it HRIS data — well beyond traditional Jira scope. Enterprise-grade controls (sandbox promotion, guest seats, multi-space views) are being assembled in parallel to make that platform pitch defensible at the CIO level.
Expect more first-party connectors that load non-Jira data (HRIS, CRM, finance) into the Teamwork Graph, paired with Rovo skills that act on it. Configuration Promotion should reach GA within a quarter.
See more alternatives to BookStack →
See more alternatives to Jira →