Ethico
The whistleblower hotline vendor is assembling a compliance suite, one module at a time.
A side-by-side editorial comparison of FreshRSS and Shiori — release velocity, themes, recent moves, and the top alternatives to consider.
FreshRSS keeps turning a reader into a queryable archive — and hardening the parts that touch the web.
Two major releases and their bug-fix follow-ups define this window. 1.28.0 added sorting and filtering by user-modified date with a matching search operator, sorting by article length, an advanced search form, an overview of dates with the most unread articles, and API-level sharing of feed visibility. 1.29.0 layered on sort-order preferences at global, category and feed level, feed-provided icons, and a purge CLI. Security work runs alongside throughout — cURL restricted to HTTP and HTTPS, reauthentication in sudo mode, Content-Security-Policy frame-ancestors, and compliance with HTTP 429 and 503 including Retry-After.
A Go bookmark manager rebuilding itself around an API — and only ever shipping release candidates.
Shiori is a self-hosted read-later and bookmark tool whose recent history is entirely release candidates: v1.7.0-rc.2, rc.3, v1.7.2-rc.1, v1.8.0-rc.1. The visible work has moved off the web UI and into an API v1 surface — tag endpoints, bookmark-tag association, filtering and counts — plus infrastructure like proxy-header authentication and SQLite performance. The last tagged release in this window is from July 2025.
Two major releases and their bug-fix follow-ups define this window. 1.28.0 added sorting and filtering by user-modified date with a matching search operator, sorting by article length, an advanced search form, an overview of dates with the most unread articles, and API-level sharing of feed visibility. 1.29.0 layered on sort-order preferences at global, category and feed level, feed-provided icons, and a purge CLI. Security work runs alongside throughout — cURL restricted to HTTP and HTTPS, reauthentication in sudo mode, Content-Security-Policy frame-ancestors, and compliance with HTTP 429 and 503 including Retry-After.
The feature line is consistently about retrieval rather than reading: search operators, sort dimensions, date overviews and per-level preferences all treat the archive as a queryable dataset instead of an inbox to clear. In parallel, the CLI surface keeps growing — purge policies, SQLite export with retention — which points at self-hosters automating maintenance rather than clicking through settings. Security fixes are steady and specific to the fact that a feed reader fetches arbitrary remote content, which is what makes the cURL protocol restriction and CSP work necessary rather than optional. Releases pair a feature drop with a fast bug-fix follow-up every time.
Given the pattern of a major release followed within weeks by a patch, and the steady expansion of CLI commands, expect the next major to continue extending search and automation surfaces rather than reworking the reading experience.
Shiori is a self-hosted read-later and bookmark tool whose recent history is entirely release candidates: v1.7.0-rc.2, rc.3, v1.7.2-rc.1, v1.8.0-rc.1. The visible work has moved off the web UI and into an API v1 surface — tag endpoints, bookmark-tag association, filtering and counts — plus infrastructure like proxy-header authentication and SQLite performance. The last tagged release in this window is from July 2025.
The project is converting from a web app with an API bolted on into an API-first service with a client, and the login component, PWA and theme work are being rewritten around that split. Proxy forward-header authentication in particular is a deployment-shape decision: it assumes Shiori sits behind an authenticating reverse proxy rather than owning identity itself. The RC-only tagging pattern makes it hard to tell what the maintainers consider stable.
The next step is presumably a final v1.8.0 consolidating the API v1 tag work, though nothing in these entries indicates the RC-to-stable promotion is scheduled. If the pattern holds, the following RC continues on API endpoints rather than the UI.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either FreshRSS or Shiori.
The whistleblower hotline vendor is assembling a compliance suite, one module at a time.
Contract automation grows up: admin permission maps, 2FA, and forms that do their own arithmetic.
The knowledge graph quietly turned itself into a meetings product.
A minimal RSS reader that made passkeys the only way in, then went back to polishing the reading experience.
A self-hosted reading server that spent two releases becoming infrastructure, then paid for it with a CVE.
Passbolt collapsed the Community-to-Pro upgrade into a settings toggle, then spent the next release on sharing transparency.
See all FreshRSS alternatives → · See all Shiori alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted — within Collab. FreshRSS and Shiori are shipping at a similar cadence (velocity 0.0 vs 0.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. FreshRSS and Shiori are shipping at a similar cadence (velocity 0.0 vs 0.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top FreshRSS alternatives in Collab are ranked by recent ship velocity. Browse the "FreshRSS alternatives" section above for the current picks, or visit /alternatives/freshrss for the full list with editorial commentary on each.
Top Shiori alternatives in Collab are ranked by recent ship velocity. Browse the "Shiori alternatives" section above for the current picks, or visit /alternatives/shiori for the full list with editorial commentary on each.