GitHub
GitHub Copilot adds adaptive model orchestration and self-resolving code review in a single week.
A side-by-side editorial comparison of HedgeDoc and Wiki.js — release velocity, themes, recent moves, and the top alternatives to consider.
A collaborative markdown editor on a security-driven maintenance cadence.
HedgeDoc's 1.x line ships every one to two months and is dominated by security response. Recent releases carry seven advisories between them — HTML injection via an email localpart, YAML frontmatter denial of service, CSRF in the Gist export, a rate-limit bypass through CF-Connecting-IP, a permission-value validation gap, missing upload security headers, and script execution in uploaded SVGs. Around those sit configuration knobs for the external-link warning, webp uploads, and rate limits.
Wiki.js 3.0 beta closes enterprise auth and SEO gaps at sprint pace
Wiki.js is running a dual-track strategy: v2.5.x is in maintenance, collecting only security and bug fixes, while v3.0.0 moves through beta weekly with substantial new features. The v3 beta has concentrated recent drops on two converging pillars — enterprise authentication (Entra ID, LDAP, SAML, Discord with group-to-role mapping) and operations infrastructure (Audit Log, admin metrics, sitemap serving, prerendering for anonymous requests). All active development runs through a single committer, shipping multiple named features per weekly beta build.
HedgeDoc's 1.x line ships every one to two months and is dominated by security response. Recent releases carry seven advisories between them — HTML injection via an email localpart, YAML frontmatter denial of service, CSRF in the Gist export, a rate-limit bypass through CF-Connecting-IP, a permission-value validation gap, missing upload security headers, and script execution in uploaded SVGs. Around those sit configuration knobs for the external-link warning, webp uploads, and rate limits.
Two threads run in parallel. The perimeter work reduces attack surface and maintenance burden at once: old API endpoints and unused config are deleted, Node 18 support is dropped now that its security window has closed, and features added in one release tend to gain an off switch in the next. The second thread is realtime correctness — concurrent-editing data loss, connections dropped mid-handshake, operations discarded during revision gap recovery — which is the only work aimed at the core editing experience rather than its edges.
Expect the 1.x line to continue as security and correctness maintenance, with more legacy endpoints and configuration removed rather than new editing features added.
Wiki.js is running a dual-track strategy: v2.5.x is in maintenance, collecting only security and bug fixes, while v3.0.0 moves through beta weekly with substantial new features. The v3 beta has concentrated recent drops on two converging pillars — enterprise authentication (Entra ID, LDAP, SAML, Discord with group-to-role mapping) and operations infrastructure (Audit Log, admin metrics, sitemap serving, prerendering for anonymous requests). All active development runs through a single committer, shipping multiple named features per weekly beta build.
The v3 beta is systematically filling the gaps that have kept Wiki.js out of enterprise environments: SSO across major identity providers, compliance tooling, SEO readiness, and theme customization for whitelabeled deployments. Each week's build adds a category that a production deployment actually requires. The remaining areas not yet visible in the beta changelog are storage/sync providers and full editor-module parity with v2 — those gaps are the logical preconditions for an RC.
The next beta cycle will likely address storage backends and remaining editor modules. A release candidate becomes the natural next step once those surface areas are covered.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either HedgeDoc or Wiki.js.
GitHub Copilot adds adaptive model orchestration and self-resolving code review in a single week.
Asana embeds AI into Slack threads and closes the rich-text gap with Notion
Hive is building shared AI automation infrastructure into the core of its PM platform.
SiYuan is actively developing AI agent capabilities that control the note-taking environment itself, from database field configuration to workspace settings.
Teable ships Scheduled Routines and Composio connections, gaining both a scheduler and an integration bus in one release
KACE stays in maintenance mode: Patch Tuesday catalogs and targeted bug fixes dominate
See all HedgeDoc alternatives → · See all Wiki.js alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted — within Collab. Wiki.js is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Wiki.js is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top HedgeDoc alternatives in Collab are ranked by recent ship velocity. Browse the "HedgeDoc alternatives" section above for the current picks, or visit /alternatives/hedgedoc for the full list with editorial commentary on each.
Top Wiki.js alternatives in Collab are ranked by recent ship velocity. Browse the "Wiki.js alternatives" section above for the current picks, or visit /alternatives/wiki-js for the full list with editorial commentary on each.