SiYuan
SiYuan stabilises 3.8.1 after a seven-build beta run, all of it widening the agent surface it opened in 3.8.0
A side-by-side editorial comparison of CommaFeed and HedgeDoc — release velocity, themes, recent moves, and the top alternatives to consider.
CommaFeed is patching its way through the attack surface a self-hosted reader inherits
CommaFeed's 7.x line has become a sustained security pass. The newest patch closes Host header injection on the password recovery endpoint and adds a commafeed.password-recovery-public-base-url setting so the email base URL is configured rather than taken from the request. Behind it: local address blocking made secure by default alongside Google Reader API support in 7.3.0, javascript: URLs filtered at parse time in 7.2.1, and SSRF limits on the image proxy in 7.2.0.
HedgeDoc 1.x releases are now mostly advisories — security in, features rarely.
The 1.x line ships on a roughly six-to-eight-week rhythm, and almost every release leads with security fixes: HTML injection through an email localpart, YAML frontmatter denial-of-service, CSRF in the Gist export, a rate-limit bypass via the CF-Connecting-IP header, SVG upload script execution. Around that, the recent additions are operator controls — an external-link warning page with a whitelist, configurable login and signup rate limits, an option to restrict uploads to registered users or disable them entirely.
CommaFeed's 7.x line has become a sustained security pass. The newest patch closes Host header injection on the password recovery endpoint and adds a commafeed.password-recovery-public-base-url setting so the email base URL is configured rather than taken from the request. Behind it: local address blocking made secure by default alongside Google Reader API support in 7.3.0, javascript: URLs filtered at parse time in 7.2.1, and SSRF limits on the image proxy in 7.2.0.
Every release in this stretch closes a path where content or a request from outside the instance was trusted too far - feed URLs reaching internal addresses, proxied images, javascript: links, and now a header shaping an outbound email. That is the checklist of a project being run as a multi-user hosted service rather than a single-user tool, and it follows directly from the 7.0.0 decision to sandbox filter expressions. Feature work continues in parallel but is clearly the smaller half.
The remaining untrusted-input surfaces - OPML import and the feed fetcher's redirect handling - are the likely next targets. The pattern of shipping each fix as its own patch release should continue rather than batching them.
The 1.x line ships on a roughly six-to-eight-week rhythm, and almost every release leads with security fixes: HTML injection through an email localpart, YAML frontmatter denial-of-service, CSRF in the Gist export, a rate-limit bypass via the CF-Connecting-IP header, SVG upload script execution. Around that, the recent additions are operator controls — an external-link warning page with a whitelist, configurable login and signup rate limits, an option to restrict uploads to registered users or disable them entirely.
This reads as a mature collaborative editor in hardening mode. New settings appear where an administrator needed a lever, not where a user asked for a feature, and the one substantial correctness fix in the window — data loss when five or more people edited a document at once — was a repair to the existing operational-transform client rather than new ground. Node 24 support and the removal of dead config options point the same direction: keeping a working product current.
Expect the next 1.x release to follow the same shape — one or more advisories plus a small configuration option — since every release in this window has done so.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either CommaFeed or HedgeDoc.
SiYuan stabilises 3.8.1 after a seven-build beta run, all of it widening the agent surface it opened in 3.8.0
Hive ships in batches, and this one is all planning accuracy and admin control.
Teable ships daily, and the work has moved from grid features to platform governance.
Simpplr publishes the research that names the gap, then ships the product that closes it.
NetNewsWire's 7.1.3 train has moved from rebuilding sync to sweeping up what the rebuild disturbed.
Document360 rebuilt its API for agents; now it's turning the AI inward on authoring.
See all CommaFeed alternatives → · See all HedgeDoc alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted, security-hardening — within Collab. CommaFeed is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. CommaFeed is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top CommaFeed alternatives in Collab are ranked by recent ship velocity. Browse the "CommaFeed alternatives" section above for the current picks, or visit /alternatives/commafeed for the full list with editorial commentary on each.
Top HedgeDoc alternatives in Collab are ranked by recent ship velocity. Browse the "HedgeDoc alternatives" section above for the current picks, or visit /alternatives/hedgedoc for the full list with editorial commentary on each.