RSelenium
RSelenium's only release in eight years touched documentation and CI, nothing else.
A side-by-side editorial comparison of Cronicle and Windmill — release velocity, themes, recent moves, and the top alternatives to consider.
Cronicle has spent 2026 hardening the paths that let a scheduler run arbitrary commands
Every release in the current window is security work. Since May, Cronicle has shipped eleven versions consisting almost entirely of dependency vulnerability bumps and authorization tightening — shell-quote twice, sanitize-html three times, ws, nodemailer, nanoid, and a move off the unmaintained bcrypt-node. The 0.9.124 and 0.9.125 releases go further, restricting event parameters to those a plugin declares and reworking authorization for job logs, event placement and manual run targets. No new user-facing capability appears anywhere in the window.
Windmill is dismantling the paywall between itself and the data stack
Three of the last six releases are directional: dbt projects running unmodified as a first-class runtime, BigQuery and Snowflake dropping out of the Enterprise tier, and AI sessions enabled by default in beta. Around them sits careful platform work — workspace lineage as the single deployment target, arbitrary-target Compare & Deploy, schema contracts for DuckLake consumers, and in-app git-to-Windmill sync. Entries are written with migration notes and upgrade paths, which is the tone of a product being run by people who expect it in production.
Every release in the current window is security work. Since May, Cronicle has shipped eleven versions consisting almost entirely of dependency vulnerability bumps and authorization tightening — shell-quote twice, sanitize-html three times, ws, nodemailer, nanoid, and a move off the unmaintained bcrypt-node. The 0.9.124 and 0.9.125 releases go further, restricting event parameters to those a plugin declares and reworking authorization for job logs, event placement and manual run targets. No new user-facing capability appears anywhere in the window.
This is what a job scheduler's maturity looks like. Cronicle's core function — running commands on remote servers on a schedule — means every authorization gap is a remote execution path, and the fixes cluster precisely there: who may launch an event, against which targets, with which parameters, and what they can read afterward. The dependency bumps follow the same logic, since a scheduler's supply chain is part of its attack surface. Feature development appears to be paused, or at least invisible in the release notes, while this work continues.
The cadence of roughly one release every one to two weeks, each carrying a dependency bump or an authorization fix, is likely to continue while the audit runs its course. sanitize-html has now been bumped in three separate releases, so expect it to reappear rather than settle.
Three of the last six releases are directional: dbt projects running unmodified as a first-class runtime, BigQuery and Snowflake dropping out of the Enterprise tier, and AI sessions enabled by default in beta. Around them sits careful platform work — workspace lineage as the single deployment target, arbitrary-target Compare & Deploy, schema contracts for DuckLake consumers, and in-app git-to-Windmill sync. Entries are written with migration notes and upgrade paths, which is the tone of a product being run by people who expect it in production.
The company is aiming squarely at data teams and removing every obstacle between them and a self-hosted trial: bring the dbt project as-is, query the warehouse on the community edition, and let the AI build scripts and flows behind the existing draft-and-diff review gate. The governance work advances at the same pace, so the free surface widens without the deployment story loosening. Enterprise is being narrowed to Oracle, MS SQL, and scale rather than to the workloads data teams actually run.
With dbt lineage and DuckLake schema contracts both landed, the likely next step is unifying them — a single asset graph spanning dbt models and materialized tables, with contract validation running across the boundary.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Cronicle or Windmill.
RSelenium's only release in eight years touched documentation and CI, nothing else.
servr keeps growing from a static file server into a general-purpose R web server.
Rhino's release line runs on release candidates, and 1.12 makes room for coding agents.
Resend is wiring itself into every agent runtime it can reach, one standard at a time
vdiffr finished its job in 2021 and has been tracking compilers ever since.
The deployment client is being rebuilt around credentials it never has to store.
See all Cronicle alternatives → · See all Windmill alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted — within Infra & APIs. Windmill is currently shipping more aggressively (velocity 8.8 vs 5.0), with 3 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Windmill is currently shipping more aggressively (velocity 8.8 vs 5.0), with 3 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Cronicle alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Cronicle alternatives" section above for the current picks, or visit /alternatives/cronicle for the full list with editorial commentary on each.
Top Windmill alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Windmill alternatives" section above for the current picks, or visit /alternatives/windmill for the full list with editorial commentary on each.