← Back to home
Comparison · PM

Flowable vs Wakapi

A side-by-side editorial comparison of Flowable and Wakapi — release velocity, themes, recent moves, and the top alternatives to consider.

Flowable vs Wakapi: at a glance

FeatureFlowableWakapi
SectorPMPM
Velocity score0.02.5
Sparks · 30d00
Top themesbpmn-cmmn, spring-boot-upgrades, breaking-changes, engine-only-scopetime-tracking, self-hosted, oidc, auth-bypass
Last editorial update15d ago58m ago
WebsiteVisit →Visit →

What is Flowable?

Flowable ships once a year and spends it on the Java platform, not on the process engine.

Flowable's release history is a slow major-version cadence — 7.0.0 in 2023, 7.1.0 in 2024, 7.2.0 in 2025, 8.0.0 in February 2026 — and each major is anchored to a Java-ecosystem jump rather than to process modelling itself. Flowable 8 moves to Spring Framework 7 and Spring Boot 4, makes Jackson 3 the default, and removes JUnit 3 and JUnit 4 support outright. The engine-level additions that do arrive, like lambda expressions in expressions, are incremental extensions to BPMN and CMMN semantics.

Read the full Flowable trajectory →

What is Wakapi?

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

Read the full Wakapi trajectory →

Flowable vs Wakapi: editorial side-by-side

F0.0

Flowable ships once a year and spends it on the Java platform, not on the process engine.

◆ Current state

Flowable's release history is a slow major-version cadence — 7.0.0 in 2023, 7.1.0 in 2024, 7.2.0 in 2025, 8.0.0 in February 2026 — and each major is anchored to a Java-ecosystem jump rather than to process modelling itself. Flowable 8 moves to Spring Framework 7 and Spring Boot 4, makes Jackson 3 the default, and removes JUnit 3 and JUnit 4 support outright. The engine-level additions that do arrive, like lambda expressions in expressions, are incremental extensions to BPMN and CMMN semantics.

◆ Where it's heading

This is a project whose roadmap is largely set by the platform underneath it. Each major forces a coordinated upgrade on adopters — Java 17 and Jakarta 9 at 7.0.0, Spring Boot 4 and Jackson 3 at 8.0.0 — and in exchange delivers query, variable and migration refinements aimed at large existing deployments. The 7.0.0 decision to drop the UI applications and the content, form and Mule modules set the pattern: narrow to the engines and the REST APIs, and let everything else go.

◆ Prediction

Expect the next major to track the following Spring and Java LTS jump on roughly the same annual rhythm. Nothing in these entries points to an AI or agent-facing direction, so any such move would be a genuine departure rather than a continuation.

W2.5

A critical auth bypass lands in the middle of Wakapi's slow identity rebuild.

◆ Current state

Wakapi's recent releases cluster around identity and deployment rather than time tracking itself: OpenID Connect login, then an OIDC-only mode, multiple API keys per user, and a switch from Alpine to a distroless nonroot container image. The 2.17.x line has carried two security fixes now — a responsibly disclosed issue in 2.17.3, and a critical authentication bypass in 2.17.6 caused by a shared cache key namespace. Release notes are mostly bare issue numbers, so several entries state that something changed without saying what.

◆ Where it's heading

The direction is a self-hosted tool making itself deployable somewhere other than one developer's server. External identity providers, an option to disable local login entirely, per-key credentials and a container that runs as a nonroot user are the requirements that come from someone else's security review. The 2.17.6 bypass sits awkwardly against that: a cache keyed without proper namespacing is exactly the class of bug that multi-tenant deployment surfaces, which suggests the auth work is now being exercised harder than the code was written for. Releases have also thinned to roughly one a month from a much faster earlier cadence.

◆ Prediction

The identity and packaging thread is the only sustained one in this feed, so further hardening in that area is the most likely continuation; the sparse release notes make anything more specific guesswork.

Alternatives to Flowable and Wakapi

Other PM products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Flowable or Wakapi.

See all Flowable alternatives → · See all Wakapi alternatives →

Recent activity from Flowable and Wakapi

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 7h agoWakapiCritical auth bypass from a shared cache key namespace
  2. 1mo agoWakapiRelease 2.17.5
  3. 2mo agoWakapiRelease 2.17.4
  4. 4mo agoWakapiSecurity fix, relay endpoint dropped, summaries may need regenerating
  5. 5mo agoWakapiDistroless nonroot container image; SQLite permissions need fixing
  6. 5mo agoFlowableSpring Boot 4 and Jackson 3 required; JUnit 4 support removed
  7. 6mo agoWakapiOIDC-only login mode disables local accounts
  8. 0y agoFlowableAsync variables, skip expressions and broader query filters
  9. 1y agoFlowableLiquibase dropped from App, CMMN, DMN and event registry engines
  10. 2y agoFlowableBug-fix release adding async leave and LocalDate timers
  11. 2y agoFlowableSpring Boot 3.1.6 support and dynamic event subscriptions
  12. 2y agoFlowableJava 17 rebase; UI apps, content and form engines removed

Frequently asked questions

What is the difference between Flowable and Wakapi?

They serve adjacent needs but don't currently overlap on shipped themes. Wakapi is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is Flowable better than Wakapi?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Wakapi is currently shipping more aggressively (velocity 2.5 vs 0.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other PM products to evaluate alongside.

What are the best alternatives to Flowable?

Top Flowable alternatives in PM are ranked by recent ship velocity. Browse the "Flowable alternatives" section above for the current picks, or visit /alternatives/flowable for the full list with editorial commentary on each.

What are the best alternatives to Wakapi?

Top Wakapi alternatives in PM are ranked by recent ship velocity. Browse the "Wakapi alternatives" section above for the current picks, or visit /alternatives/wakapi for the full list with editorial commentary on each.