Windmill
Windmill absorbed dbt, un-gated its warehouse languages, and turned AI authoring on by default.
A side-by-side editorial comparison of Casdoor and NetBox — release velocity, themes, recent moves, and the top alternatives to consider.
Nine releases in four days, all of them small — Casdoor is grinding on tenant-level governance.
Casdoor is running an unusually tight release train: nine tagged versions between August 1 and August 4, each carrying one or two commits. The content clusters around two areas. Retention and expiry are becoming per-organization settings — configurable record retention days, configurable token retention days, and automatic permission revocation after a set expiry. Separately, OAuth conformance work continues, with the RFC 8707 resource parameter now preserved through both the consent flow and the fast auto-signin path, plus a backchannel logout URL field on the application edit page.
NetBox is spending 4.6 paying down query cost, not adding models.
The 4.6 line opened in May with genuinely new modelling — virtual machine types, cable bundles, a flat rack-group axis, ETag support on the REST API — and every patch release since has been maintenance in the same shape: a handful of enhancements, a block of performance work, a longer block of bug fixes. The performance entries are consistently about query count: N+1 elimination in GraphQL, prefetch hints, serializer caching, chunked bulk updates, a GIN index on cable paths.
Casdoor is running an unusually tight release train: nine tagged versions between August 1 and August 4, each carrying one or two commits. The content clusters around two areas. Retention and expiry are becoming per-organization settings — configurable record retention days, configurable token retention days, and automatic permission revocation after a set expiry. Separately, OAuth conformance work continues, with the RFC 8707 resource parameter now preserved through both the consent flow and the fast auto-signin path, plus a backchannel logout URL field on the application edit page.
The per-organization retention and expiry settings point at multi-tenant deployments where each tenant carries its own compliance obligations — a single global retention policy stops working once one organization's auditor wants 90 days and another's wants 400. The RFC 8707 work is narrower but pointed: resource indicators bind a token to the API it was issued for, which matters when one identity provider fronts many services. A batch UpdatePermissions API added to cut Casbin enforcer rebuilds suggests some deployments are large enough that permission writes had become a bottleneck.
The retention-and-expiry pattern is not finished — record and token retention are now per-organization, and other lifecycle settings are the obvious next candidates. Expect the release cadence to stay at this granularity, since these tags carry single commits rather than batched releases.
The 4.6 line opened in May with genuinely new modelling — virtual machine types, cable bundles, a flat rack-group axis, ETag support on the REST API — and every patch release since has been maintenance in the same shape: a handful of enhancements, a block of performance work, a longer block of bug fixes. The performance entries are consistently about query count: N+1 elimination in GraphQL, prefetch hints, serializer caching, chunked bulk updates, a GIN index on cable paths.
This is a project optimising for large installations rather than new use cases. GraphQL in particular is being hardened release by release — depth limiting, prefetch hints, schema corrections — which reads as API consumers hitting limits at scale. Security fixes arrive quietly inside the same lists, including audit-trail immutability and constant-time token comparison.
Expect the 4.6.x train to continue on its roughly two-week cadence with the same enhancement/performance/fix mix, and the next feature-bearing work to wait for 4.7 rather than appearing in a patch.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Casdoor or NetBox.
Windmill absorbed dbt, un-gated its warehouse languages, and turned AI authoring on by default.
Resend spent a month making itself something agents and third-party apps can log into.
Prowler turned its assistant from a read-only explainer into something that can change your tenant.
Depot is no longer a build accelerator — it is assembling the whole CI stack underneath itself.
Buildkite is rebuilding its MCP server around what an agent actually does with a failed build.
The self-hosted dashboard finally let you drag things around instead of editing YAML.
See all Casdoor alternatives → · See all NetBox alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Casdoor and NetBox are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Casdoor and NetBox are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Casdoor alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Casdoor alternatives" section above for the current picks, or visit /alternatives/casdoor for the full list with editorial commentary on each.
Top NetBox alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "NetBox alternatives" section above for the current picks, or visit /alternatives/netbox for the full list with editorial commentary on each.