Teable
Secrets get encrypted at rest while the computed-field engine keeps getting shored up
A side-by-side editorial comparison of EGroupware and HumHub — release velocity, themes, recent moves, and the top alternatives to consider.
EGroupware's feed has become a security treadmill, with the 23.1 branch days from end of life.
Almost every release in this window is a security release, and most ship as a pair — one build for 26.x, an identical-scope backport for 23.1. Feature work exists but arrives as single lines inside those security notes: WebAuthN two-factor moving out of the former EPL add-on, OpenID bumped to current upstream libraries, invoice XML gaining reverse-charge exemption codes. The recurring theme in the fixes themselves is authentication — OAuth bearer tokens, OpenID regressions, an inverted email_verified check, passkeys broken by a missing proxy config.
HumHub's public feed carries only betas, and 1.19's is still about surviving the upgrade.
The four releases visible here are all pre-release: 1.19.0-beta.2 and beta.1, and 1.18.0-beta.6 and beta.5 before them. The 1.19 line is dominated by upgrade-path and data-integrity repair — a foreign key violation aborting the comment content_id migration on databases with orphaned rows, fatal errors when purging content whose underlying record was gone, and in beta.2 a fatal SCSS build loop left behind when the 1.19 move of static/themes into protected/humhub stranded an empty theme skeleton. Beta.2 also fixes a real leak: activities from private spaces appearing in the summary mail and dashboard of users holding only a pending invite or join request.
Almost every release in this window is a security release, and most ship as a pair — one build for 26.x, an identical-scope backport for 23.1. Feature work exists but arrives as single lines inside those security notes: WebAuthN two-factor moving out of the former EPL add-on, OpenID bumped to current upstream libraries, invoice XML gaining reverse-charge exemption codes. The recurring theme in the fixes themselves is authentication — OAuth bearer tokens, OpenID regressions, an inverted email_verified check, passkeys broken by a missing proxy config.
The project is consolidating everyone onto 26.x and has put a date on it: security coverage for 23.1 ends August 15, 2026, repeated as a warning in every 23.1 build since July. After that the twin-release pattern should stop and the cadence should halve. The authentication stack is the least settled part of the codebase right now — the July and August releases keep re-fixing OpenID and WebAuthN regressions introduced by their own predecessors.
Expect 23.1 builds to cease after August 15 and the feed to become single-track 26.x. On the evidence of the last six releases, expect at least one more OpenID or WebAuthN regression fix to follow the recent upstream library bump.
The four releases visible here are all pre-release: 1.19.0-beta.2 and beta.1, and 1.18.0-beta.6 and beta.5 before them. The 1.19 line is dominated by upgrade-path and data-integrity repair — a foreign key violation aborting the comment content_id migration on databases with orphaned rows, fatal errors when purging content whose underlying record was gone, and in beta.2 a fatal SCSS build loop left behind when the 1.19 move of static/themes into protected/humhub stranded an empty theme skeleton. Beta.2 also fixes a real leak: activities from private spaces appearing in the summary mail and dashboard of users holding only a pending invite or join request.
The 1.19 cycle is being spent making the migration survivable on real installations rather than adding capability, which is the usual shape when a schema and directory-layout change meets databases and webroots that have accumulated years of drift. Beta.2 extends that into the installer itself, where an unreachable database was offering to re-set-up a live instance during a transient outage. The permission and visibility fixes point the same way: tightening authorisation and content boundaries is cleanup of an existing model, not an extension of it.
Only beta tags appear in this feed, so a 1.19.0 stable is the obvious next milestone, but nothing here dates it. The beta.1-to-beta.2 gap of about a month is a faster rhythm than the roughly six months between the 1.18 and 1.19 betas.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either EGroupware or HumHub.
Secrets get encrypted at rest while the computed-field engine keeps getting shored up
Security and governance controls catch up to the Copilot build-out
A social-networking engine in careful maintenance across two supported branches.
7.1.3 ships on the Mac, closing a release spent almost entirely on rebuilding Feedly sync.
Hive keeps tightening the same three seams: planned time, admin control, and AI review scope
A dated canary most days, with the beta line carrying the same commits later.
See all EGroupware alternatives → · See all HumHub alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. EGroupware and HumHub are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. EGroupware and HumHub are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top EGroupware alternatives in Collab are ranked by recent ship velocity. Browse the "EGroupware alternatives" section above for the current picks, or visit /alternatives/egroupware for the full list with editorial commentary on each.
Top HumHub alternatives in Collab are ranked by recent ship velocity. Browse the "HumHub alternatives" section above for the current picks, or visit /alternatives/humhub for the full list with editorial commentary on each.