ToolJet
ToolJet bundles its MCP server into the EE image as AI builder features land in the LTS track
A side-by-side editorial comparison of FOSSA CLI and werf — release velocity, themes, recent moves, and the top alternatives to consider.
fossa-cli's releases are ecosystem-by-ecosystem repairs to how lockfiles are read.
Releases arrive every one to three weeks and almost all of the substance is per-ecosystem dependency resolution. In this window: Node workspaces declared with a leading ./ now match, npm v3 lockfiles get target-level dependency scoping, pnpm lockfile handling was refactored, and sbt 1.4+ projects with an explicit DependencyTreePlugin route to the built-in command. Around that sit operational adjustments — the default scan timeout raised from 30 seconds to a minute, release-group project resolution moved to a server-side lookup — and two tags that carry nothing but a Themis version bump or a release cut.
werf ships weekly across two tracks — v3 dev gets JSON Schemas and Harbor v2 fixes, v2 alpha gets the backports.
werf operates two active release channels in parallel: v3.x ("dev") for new capabilities and v2.x ("alpha") for stabilized backports. The September 2026 sprint covers v3.3–v3.5 and v2.78–v2.79, with several meaningful improvements — JSON Schema publication for werf config files, a netavark networking requirement replacing CNI/slirp4netns, and a Harbor registry fix that clears a real registry-compatibility issue. The dual-track cadence lets teams stay on the stable alpha channel while the dev track absorbs the larger changes.
Releases arrive every one to three weeks and almost all of the substance is per-ecosystem dependency resolution. In this window: Node workspaces declared with a leading ./ now match, npm v3 lockfiles get target-level dependency scoping, pnpm lockfile handling was refactored, and sbt 1.4+ projects with an explicit DependencyTreePlugin route to the built-in command. Around that sit operational adjustments — the default scan timeout raised from 30 seconds to a minute, release-group project resolution moved to a server-side lookup — and two tags that carry nothing but a Themis version bump or a release cut.
The work is breadth-of-accuracy, not new features: every release closes a case where a real project layout produced an incomplete or wrong dependency graph. That is the correct shape for a compliance scanner, where a missed transitive dependency is a failed audit rather than a rough edge. The steady stream of package-manager-specific fixes suggests coverage is still being driven by customer projects that scan badly, which means the tail of ecosystems is long and being worked through one at a time.
Expect the pattern to continue with another package manager's lockfile format — the timeout increase hints scans are also getting slower on large monorepos, so performance work on the same paths is likely next.
werf operates two active release channels in parallel: v3.x ("dev") for new capabilities and v2.x ("alpha") for stabilized backports. The September 2026 sprint covers v3.3–v3.5 and v2.78–v2.79, with several meaningful improvements — JSON Schema publication for werf config files, a netavark networking requirement replacing CNI/slirp4netns, and a Harbor registry fix that clears a real registry-compatibility issue. The dual-track cadence lets teams stay on the stable alpha channel while the dev track absorbs the larger changes.
werf's dev track is progressively expanding its deploy primitives: renderPatches support, returning rendered resources from ReleaseInstall, and authenticated secret write capability (v3.3.0) all suggest a push toward more programmable, auditable deploy pipelines. The embedded Deno binary in v3.2.0 — bundled behind a feature gate — hints at scripted deployment hooks as a coming capability. JSON Schemas for werf config files make editor tooling a first-class citizen.
The Deno embedding will likely surface as a supported scripting API for pre/post-deploy hooks in the next major dev release. A corresponding migration of Helm-centric users toward werf's native deploy primitives appears to be the longer arc.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either FOSSA CLI or werf.
ToolJet bundles its MCP server into the EE image as AI builder features land in the LTS track
GitHub adds Claude Opus 5.5 and GPT-6 models while shipping sandboxed agent execution
Parse Server patches three security CVEs: GraphQL disclosure and protectedFields bypass
Buildkite ships Agent v4, an MCP server for AI-native CI, and a VS Code extension in a dense September push.
Jackett's daily tracker churn adds 11 new APIs and formalizes its security policy in a week
Chromatic ships Vitest Browser Mode and React Native visual testing, moving beyond Storybook
See all FOSSA CLI alternatives → · See all werf alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. FOSSA CLI and werf are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. FOSSA CLI and werf are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top FOSSA CLI alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "FOSSA CLI alternatives" section above for the current picks, or visit /alternatives/fossa-cli for the full list with editorial commentary on each.
Top werf alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "werf alternatives" section above for the current picks, or visit /alternatives/werf for the full list with editorial commentary on each.