GravityKit
GravityKit ships weekly across a whole plugin suite, with an MCP server now part of the lineup.
A side-by-side editorial comparison of GoCD and Casdoor — release velocity, themes, recent moves, and the top alternatives to consider.
GoCD's changelog is one maintainer keeping a 2010s CI server running on current runtimes.
The visible work is almost entirely platform upkeep, and nearly all of it is authored by a single contributor. The baseline has been walked forward repeatedly — Java 17 minimum, then building and packaging on Java 21, then Java 21 as the hard minimum with macOS x64 support dropped — while container images moved from Alpine and CentOS Stream to Wolfi and Chainguard, Rails went from 6.1 through 7.1, and Hamcrest was replaced by AssertJ across the test suite. 26.1.0 is the exception in substance: it carries security fixes described as affecting all prior GoCD versions, with an explicit recommendation to upgrade as soon as possible.
Casdoor ships a version per commit — three tags in one day, one feature each.
Casdoor is a self-hosted identity and access platform, and its release process is unusually granular: 3.140.0 through 3.144.0 landed in four days, three of them on August 6 alone, each carrying a single commit. The changes in this window are administrative rather than architectural — per-organization record retention, a properties field on products, a column widened for provider scopes, and Casbin group rules following a user through a rename. Titles are bare version numbers, so the feed reads as noise unless you open each tag.
The visible work is almost entirely platform upkeep, and nearly all of it is authored by a single contributor. The baseline has been walked forward repeatedly — Java 17 minimum, then building and packaging on Java 21, then Java 21 as the hard minimum with macOS x64 support dropped — while container images moved from Alpine and CentOS Stream to Wolfi and Chainguard, Rails went from 6.1 through 7.1, and Hamcrest was replaced by AssertJ across the test suite. 26.1.0 is the exception in substance: it carries security fixes described as affecting all prior GoCD versions, with an explicit recommendation to upgrade as soon as possible.
This is a mature product in custodial maintenance rather than development. The pattern across releases is dependency deduplication, dead code removal, deprecation cleanup and base image swaps — the work that keeps a large Rails and Java codebase installable and patchable on current operating systems. Feature entries are rare enough that their absence, rather than any particular change, is the signal.
Given the security advisory in 26.1.0 covers all earlier versions and the release notes point offsite for detail, the practical next step for operators is that upgrade. The entries show no queued feature work to project from.
Casdoor is a self-hosted identity and access platform, and its release process is unusually granular: 3.140.0 through 3.144.0 landed in four days, three of them on August 6 alone, each carrying a single commit. The changes in this window are administrative rather than architectural — per-organization record retention, a properties field on products, a column widened for provider scopes, and Casbin group rules following a user through a rename. Titles are bare version numbers, so the feed reads as noise unless you open each tag.
Two threads are worth separating from the churn. The first is authorization correctness: moving Casbin group rules on rename and cleaning up records on a cancelled add both close gaps where permission state drifts from the objects it describes. The second is OAuth conformance — 3.140.0 preserves the RFC 8707 resource indicator through the fast auto-signin path, which is the parameter that scopes a token to a specific downstream API. Neither is announced as a theme; both are visible in the commit stream.
Expect the same cadence of single-commit releases to continue, with more OAuth and OIDC conformance details filled in as they are reported. Nothing here signals a larger 3.x milestone or a break in versioning.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either GoCD or Casdoor.
GravityKit ships weekly across a whole plugin suite, with an MCP server now part of the lineup.
After a two-year redesign, LibreSpeed is adding tests instead of polishing pixels.
A security advisory cycle forced Nautobot to break its REST API on both supported branches at once.
Gatekeeper grew a package manager for policies — and a benchmark to prove they are not too slow.
Incus settled its 7.0 LTS, then went straight back to a monthly feature cadence.
Firecracker's microVMs can now grow and shrink devices while running.
See all GoCD alternatives → · See all Casdoor alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. GoCD and Casdoor are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. GoCD and Casdoor are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top GoCD alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "GoCD alternatives" section above for the current picks, or visit /alternatives/gocd for the full list with editorial commentary on each.
Top Casdoor alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Casdoor alternatives" section above for the current picks, or visit /alternatives/casdoor for the full list with editorial commentary on each.