DNSControl
DNSControl is rewriting its record internals in public, one release candidate at a time
A side-by-side editorial comparison of Grype and Ory Hydra — release velocity, themes, recent moves, and the top alternatives to consider.
Grype's entire roadmap is false positives — and it just went code-aware to cut them.
Almost every release in this window targets match accuracy rather than coverage. Go has taken the brunt of it: merging govulndb GO-* records with their GHSA aliases, scoping GHSA twins by shared CVE, disabling stdlib CPE matching by default, and ignoring compiler CVEs when an image contains only a compiled binary. Coverage still widens at the edges — Zarf packages, Ubuntu ESM, Chainguard OSV data, CycloneDX 1.7 input — but it is not where the effort sits.
Hydra's 2.2 candidates rebuilt the OAuth2 flow store, then reached for verifiable credentials
Ory Hydra is a self-hosted OAuth2 and OpenID Connect server. Its visible release record is the v2.2.0 candidate series from 2023, which did two substantial things: rc.2 moved authorization-code flow state out of the database and into AEAD-encrypted cookies and request parameters, a change shipped with an explicit breaking-change notice; rc.3 then added initial OIDC verifiable-credential issuance and wired logout propagation into Ory Kratos. The feed stops at a v2.2.0-pre.1 tag in February 2024.
Almost every release in this window targets match accuracy rather than coverage. Go has taken the brunt of it: merging govulndb GO-* records with their GHSA aliases, scoping GHSA twins by shared CVE, disabling stdlib CPE matching by default, and ignoring compiler CVEs when an image contains only a compiled binary. Coverage still widens at the edges — Zarf packages, Ubuntu ESM, Chainguard OSV data, CycloneDX 1.7 input — but it is not where the effort sits.
The arc runs from naive SBOM-to-CVE matching toward evidence-based matching. Reachability analysis is the clearest marker: grype is beginning to reason about whether vulnerable code is actually reachable rather than merely present. The parallel stream of ecosystem-specific correctness work — RHEL minor version streams, RHSA duplication, distro version parsing — suggests the same per-ecosystem treatment is being worked through one package manager at a time.
Reachability shipped for Go only. Extending it to a second ecosystem is the obvious next step, and Java or JavaScript are the likeliest targets given where SBOM false positives concentrate.
Ory Hydra is a self-hosted OAuth2 and OpenID Connect server. Its visible release record is the v2.2.0 candidate series from 2023, which did two substantial things: rc.2 moved authorization-code flow state out of the database and into AEAD-encrypted cookies and request parameters, a change shipped with an explicit breaking-change notice; rc.3 then added initial OIDC verifiable-credential issuance and wired logout propagation into Ory Kratos. The feed stops at a v2.2.0-pre.1 tag in February 2024.
The through-line is reducing per-request database work in the hot authorization path — first by relocating flow state into encrypted client-side material, then by parallelizing JSON web key set generation and adding scope-claim strategies. Running underneath is tighter coupling to the rest of the Ory stack: the Kratos admin URL config and session-termination hook make Hydra less of a standalone component and more of one piece of an integrated identity suite. The verifiable-credentials work is the one thread pointing somewhere genuinely new, and it shipped against a draft specification.
The candidate series points toward a v2.2.0 general release consolidating the AEAD flow change and the credential-issuance work. The feed's silence after February 2024 gives no basis for judging when, or whether the draft-stage VC support advanced.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Grype or Ory Hydra.
DNSControl is rewriting its record internals in public, one release candidate at a time
Fission's release feed carries only RC tags, and none of them say what shipped
Kaniko's release feed stops dead in June 2024 after a patch that undid its own change
mod_auth_openidc audited itself, found eight holes, and broke every session on the way out
Kubernetes CNI maintaining four release branches at once, mostly to carry CVE fixes back.
KeePass-compatible password manager frozen mid-patch-run since 2021.
See all Grype alternatives → · See all Ory Hydra alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Grype is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Grype is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Grype alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Grype alternatives" section above for the current picks, or visit /alternatives/grype for the full list with editorial commentary on each.
Top Ory Hydra alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Ory Hydra alternatives" section above for the current picks, or visit /alternatives/ory-hydra for the full list with editorial commentary on each.