incident.io
Nexus does the diagnosis; the rest is on-call plumbing
A side-by-side editorial comparison of Depot and Infisical — release velocity, themes, recent moves, and the top alternatives to consider.
| Feature | Depot | Infisical |
|---|---|---|
| Sector | Infra & APIs | Infra & APIs |
| Velocity score | 6.3 | 5.0 |
| Sparks · 30d | 1 | 0 |
| Top themes | ci-cd, build-acceleration, test-analytics, source-control | pam, pki, secret-rotation, agent-proxy |
| Last editorial update | 1d ago | 2h ago |
| Website | — | Visit → |
Depot is expanding from faster builds into the whole CI stack — tests, source control, and its own metal.
Depot has spent the last month building outward from build acceleration. Test results went generally available with JUnit ingest, org-wide flaky and slow test analytics, and timing-based shard balancing. Underneath that, Depot Metal moved CI and Sandboxes onto bare-metal microVMs the company controls end to end, and Depot Code entered private beta as a diskless git server backed by blob storage. The smaller releases fill in the surrounding surface: Tailscale access to private networks, GitLab OIDC, Datadog CI Visibility, stacked pull requests, and macOS 26 runners on M4.
PAM and PKI now take up most of the lines in Infisical's release notes.
Six releases in two weeks, each a flat PR list with no narrative. The recurring feature work is privileged access management — Redis account types and web access, filling account fields from a pasted connection string, machine identity access — and PKI, which gained AWS Private CA as an issuing authority and SCEP enrollment for Microsoft Intune. Secret management itself mostly appears as rotation coverage for Cloudflare API tokens and R2 access keys.
Depot has spent the last month building outward from build acceleration. Test results went generally available with JUnit ingest, org-wide flaky and slow test analytics, and timing-based shard balancing. Underneath that, Depot Metal moved CI and Sandboxes onto bare-metal microVMs the company controls end to end, and Depot Code entered private beta as a diskless git server backed by blob storage. The smaller releases fill in the surrounding surface: Tailscale access to private networks, GitLab OIDC, Datadog CI Visibility, stacked pull requests, and macOS 26 runners on M4.
Each layer Depot adds is one it previously rented — compute from cloud runners, source hosting from GitHub, test insight from nothing at all. Owning the storage and hypervisor tiers is what makes the performance claims possible, and owning test data is what turns a build accelerator into something that reports on the pipeline rather than just running it faster. The pattern suggests Depot is positioning as the full CI platform, with speed as the entry point rather than the product.
Depot Code should move from private to open beta with tighter Depot CI integration, since a git server the company controls is what makes source-aware caching and test selection possible. Expect the test analytics to grow toward selecting which tests to run, not only how to split them.
Six releases in two weeks, each a flat PR list with no narrative. The recurring feature work is privileged access management — Redis account types and web access, filling account fields from a pasted connection string, machine identity access — and PKI, which gained AWS Private CA as an issuing authority and SCEP enrollment for Microsoft Intune. Secret management itself mostly appears as rotation coverage for Cloudflare API tokens and R2 access keys.
Infisical is assembling a credential platform rather than a secrets store, and it is doing so without a single headline release — each pillar arrives as two or three PRs per version. PKI is furthest along: issuing from an external AWS authority and enrolling devices through Intune puts it in territory previously held by dedicated certificate products. A third thread, the agent proxy, is accumulating the parts a product needs before launch — a Google Workspace service template, last-used timestamps, and adoption telemetry for proxied services.
The agent proxy is the thread most likely to get a real announcement; service templates and usage telemetry landing now are the groundwork a launch requires.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Depot or Infisical.
Nexus does the diagnosis; the rest is on-call plumbing
Four channels, one fix stream — werf's releases are mostly concurrency repairs.
1.38.4 is a security release in all but name, closing ACL gaps across the API.
Biome's patch train keeps adding rules — and is quietly growing a Markdown linter.
DNSControl is rewriting its record internals in public, one release candidate at a time
Fission's release feed carries only RC tags, and none of them say what shipped
See all Depot alternatives → · See all Infisical alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Depot is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Depot is currently shipping more aggressively (velocity 6.3 vs 5.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Depot alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Depot alternatives" section above for the current picks, or visit /alternatives/depot for the full list with editorial commentary on each.
Top Infisical alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Infisical alternatives" section above for the current picks, or visit /alternatives/infisical for the full list with editorial commentary on each.