Sanity
Sanity is turning its CMS into agent infrastructure, one MCP patch at a time.
A side-by-side editorial comparison of containerd and HashiCorp — release velocity, themes, recent moves, and the top alternatives to consider.
containerd patches CVE-2026-53493 across five branches the same day 2.4.0 ships 658 commits
containerd maintains five active release branches simultaneously — 1.7 LTS, 2.0, 2.2, 2.3 LTS, and the new 2.4. The 2.4.0 release brings 658 commits: UpdateSandbox RPC for kubelet-to-shim update propagation, EROFS warm-image-cache with Prometheus metrics, user namespace host networking enabled by default, and removal of long-deprecated CDI and CNI config options. On the same day 2.4.0 shipped, all five branches received coordinated patches for CVE-2026-53493.
HashiCorp Vault agentic IAM reaches GA — AI agents get production-grade identity and secrets management.
HashiCorp has shipped a concentrated set of AI-adjacent infrastructure releases: Vault agentic IAM is now generally available (identity and secrets for AI agents), HCP Terraform is positioned as the control plane for AI-driven infrastructure, and Packer gains SLSA provenance for machine images. Boundary extends to mainframe access and the AzureRM provider hits a major version. The security-infrastructure layer is being re-architected for a world where agents, not humans, are making infrastructure changes.
containerd maintains five active release branches simultaneously — 1.7 LTS, 2.0, 2.2, 2.3 LTS, and the new 2.4. The 2.4.0 release brings 658 commits: UpdateSandbox RPC for kubelet-to-shim update propagation, EROFS warm-image-cache with Prometheus metrics, user namespace host networking enabled by default, and removal of long-deprecated CDI and CNI config options. On the same day 2.4.0 shipped, all five branches received coordinated patches for CVE-2026-53493.
containerd is pushing its feature surface further into CRI-level orchestration — the UpdateSandbox RPC lets orchestrators propagate sandbox updates to shims without container restarts, and the mount manager for image mounts gives runtimes finer-grained control over image lifecycle. EROFS snapshotter investments (warm-image-cache, Prometheus metrics, blob source recording) suggest it's being positioned as the default for read-heavy workloads. Windows is getting production-grade attention with log streaming support.
The NRI plugin deprecation warnings shipped in 2.4 set up a clean-break removal in a future release; 2.5 will likely complete that migration. Expect EROFS snapshotter to graduate from experimental to recommended as the metrics instrumentation matures and field adoption data accumulates.
HashiCorp has shipped a concentrated set of AI-adjacent infrastructure releases: Vault agentic IAM is now generally available (identity and secrets for AI agents), HCP Terraform is positioned as the control plane for AI-driven infrastructure, and Packer gains SLSA provenance for machine images. Boundary extends to mainframe access and the AzureRM provider hits a major version. The security-infrastructure layer is being re-architected for a world where agents, not humans, are making infrastructure changes.
The consistent signal is that HashiCorp is treating AI agents as a first-class principal in the infrastructure identity model. Vault agentic IAM, HCP Terraform's agentic control plane story, and SLSA provenance work all point the same direction: infrastructure that remains auditable and policy-controlled even when no human is directly in the loop. This is an extension of HashiCorp's existing zero-trust position, not a pivot.
The next likely move is expanding Vault agentic IAM into Terraform-native configurations and deeper Boundary integration, so that an AI agent's access scope can be defined alongside infrastructure-as-code. The mainframe Boundary integration suggests enterprise verticals are a near-term growth target.
Other DevOps products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either containerd or HashiCorp.
Sanity is turning its CMS into agent infrastructure, one MCP patch at a time.
Manticore Search adds direct-to-disk bulk import, eliminating RAM staging bottlenecks in large ingestion pipelines.
CodeRabbit launches a cross-repo PR triage queue that ranks every open pull request with evidence.
GitHub turns Copilot into an org-wide default, adds memory to agentic security fixes.
Rivet is shipping the complete agentic backend stack: actors, durable streams, BYOC, MCP integration, and a V8 app runtime in one month.
Scalingo ships routine runtime maintenance at high cadence while expanding database observability through its SDK.
See all containerd alternatives → · See all HashiCorp alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — security — within DevOps. HashiCorp is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. HashiCorp is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other DevOps products to evaluate alongside.
Top containerd alternatives in DevOps are ranked by recent ship velocity. Browse the "containerd alternatives" section above for the current picks, or visit /alternatives/containerd for the full list with editorial commentary on each.
Top HashiCorp alternatives in DevOps are ranked by recent ship velocity. Browse the "HashiCorp alternatives" section above for the current picks, or visit /alternatives/hashicorp for the full list with editorial commentary on each.