Sanity
Sanity is rebuilding its CMS around agents, shipping an MCP release almost every day.
A side-by-side editorial comparison of GitHub and Parse Server — release velocity, themes, recent moves, and the top alternatives to consider.
GitHub opens Copilot code review to the API and moves advisory triage onto structured, private rails.
Two days after putting computer use into Copilot, GitHub spent October 2 on plumbing. Copilot code review can now be requested through REST and GraphQL with a per-request effort level, a batch of older Copilot models was retired across every surface, and stateless App installation tokens are now the default. Security advisories gained confidential maintainer comments, a comments API in public preview, and five new GraphQL fields.
Parse Server keeps closing permission gaps, three fixes in a single day.
Every 9.10.2 alpha in the last ten days is a fix, and the run of fixes is speeding up: three alphas shipped on October 2 alone. The fixes cluster on access control: class-level permissions not enforced before schema validation, LiveQuery ignoring protectedFields exemptions, and a GraphQL rate-limit path that did nothing. Two more carry GitHub security advisories for server crashes and batch transactions that could block other clients' writes.
Two days after putting computer use into Copilot, GitHub spent October 2 on plumbing. Copilot code review can now be requested through REST and GraphQL with a per-request effort level, a batch of older Copilot models was retired across every surface, and stateless App installation tokens are now the default. Security advisories gained confidential maintainer comments, a comments API in public preview, and five new GraphQL fields.
Copilot is being turned into callable infrastructure: code review that other pipelines can trigger and tune is the same move as dynamic workflows and the SDK, applied to review. On the security side, GitHub is building a full intake-to-resolution workflow for vulnerability reports, with rate limits and forms at the front and private discussion and API access at the back.
Expect Copilot code review to show up as a configurable step in Actions and agent workflows now that it has an API and effort levels. The advisory comments API is likely to leave preview quickly, given how many advisory changes shipped in two days.
Every 9.10.2 alpha in the last ten days is a fix, and the run of fixes is speeding up: three alphas shipped on October 2 alone. The fixes cluster on access control: class-level permissions not enforced before schema validation, LiveQuery ignoring protectedFields exemptions, and a GraphQL rate-limit path that did nothing. Two more carry GitHub security advisories for server crashes and batch transactions that could block other clients' writes.
The project is closing the gaps between configured policy and enforced behaviour, especially where LiveQuery and GraphQL diverge from the REST path. Options that were silently ignored (graphQLPublicIntrospection, the requestPath rate limit, protectedFieldsOwnerExempt) are being made to work, which tightens the security posture without adding surface.
Expect more 9.10.2 alphas aimed at LiveQuery and GraphQL parity with REST permissions, then a stable 9.10.2 that bundles them; the entries show no sign of feature work in the near term.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Tap any card for the full editorial trajectory or compare directly with GitHub.
Sanity is rebuilding its CMS around agents, shipping an MCP release almost every day.
CodeRabbit lets its PR bot act on its own, and keeps widening where it can run.
Gravity Forms stays on a patch cadence: another core security release, little direction change.
Rivet is turning its actor runtime into the enterprise backend for AI agents.
Dapr opens the 1.19 cycle while three release lines absorb workflow and actor fixes.
Weaviate is competing on memory footprint while patching a credential leak.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Tap any card for the full editorial trajectory or compare directly with Parse Server.
Kinsta builds out operator controls: emergency suspension, bulk actions and disaster recovery.
Buildkite is tightening fleet discipline while opening its controls to agents.
Railway's weekly cadence is building a PaaS for AI agents: MCP, Cloud Agents, no-barrier entry.
Jackett ships daily and nothing changes direction: the work is keeping hundreds of indexers alive.
Redocly is in a maintenance groove: daily Reunite fixes and a config schema that keeps getting tidier.
ToolJet starts enforcing Cloud workspace limits as its AI app builder moves to paid tiers.
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. GitHub is currently shipping more aggressively (velocity 10.0 vs 5.0), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. GitHub is currently shipping more aggressively (velocity 10.0 vs 5.0), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top GitHub alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "GitHub alternatives" section above for the current picks, or visit /alternatives/github for the full list with editorial commentary on each.
Top Parse Server alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Parse Server alternatives" section above for the current picks, or visit /alternatives/parse-server for the full list with editorial commentary on each.