MISP
MISP 2.5.46 delivers a 50× sightings query speedup and systematic SSRF closure — serious infrastructure work.
A side-by-side editorial comparison of Helm and werf — release velocity, themes, recent moves, and the top alternatives to consider.
Helm 3 ships its final minor release while Helm 4.3 eliminates multi-minute status computation delays.
Helm is running two parallel release trains. Helm 3.22.0, released alongside 4.3.0, is officially the last Helm 3 minor release — patch-only from here until end of life. Helm 4 is the active development path, with 4.3.0 delivering real performance work: concurrent status computation removes what were previously multi-minute stalls on large deployments. The consistent k8s-io group bumps across both branches reflect ongoing Kubernetes version alignment.
werf v3.x dev channel drops CNI for netavark networking while the 2.x alpha track holds to bug fixes
werf maintains two active release channels: a 2.x alpha series (at v2.78.2) focused almost entirely on correctness backports — stapel panics, cache repo handling, import failures on symlinked paths — and a v3.x dev series pushing new capabilities. The v3.x track added authenticated secret values in deploy pipelines, renderPatches support, and a hard networking dependency switch in v3.4.0-dev.
Helm is running two parallel release trains. Helm 3.22.0, released alongside 4.3.0, is officially the last Helm 3 minor release — patch-only from here until end of life. Helm 4 is the active development path, with 4.3.0 delivering real performance work: concurrent status computation removes what were previously multi-minute stalls on large deployments. The consistent k8s-io group bumps across both branches reflect ongoing Kubernetes version alignment.
With Helm 3 in maintenance, the team's attention fully consolidates on Helm 4. The 4.3.0 changes — concurrent status computation, ownership verification at uninstall, SOURCE_DATE_EPOCH support for reproducible archives — indicate that Helm 4 is prioritizing safety for GitOps and CI/CD workflows at scale. The resync period cut from 1 hour to 3 minutes points toward tighter reconciliation loops for teams running Helm as infrastructure management rather than one-shot deploy tooling.
Helm 4.4.0 (scheduled January 2027) will likely continue hardening uninstall safety and improving OCI registry interactions. Helm 3 will receive security patches only — teams still on v3 should treat the end-of-life announcement as a migration deadline.
werf maintains two active release channels: a 2.x alpha series (at v2.78.2) focused almost entirely on correctness backports — stapel panics, cache repo handling, import failures on symlinked paths — and a v3.x dev series pushing new capabilities. The v3.x track added authenticated secret values in deploy pipelines, renderPatches support, and a hard networking dependency switch in v3.4.0-dev.
The v3.x dev channel is where werf's actual evolution happens: embedded Deno for deploy scripting (v3.2.0), the netavark networking switch (v3.4.0), and a systematic race-condition fix campaign across build, deploy, and registry layers. The 2.x alpha track functions as a backport target for correctness fixes, not a destination for new features. Registry-side cleanup reporting and Helm surface improvements in 3.x suggest the team is hardening the GitOps workflow layer before calling v3 stable.
The netavark switch in v3.4.0-dev is a hard breaking change — environments without netavark installed will lose rootless build capability. Expect migration documentation and a compatibility fallback discussion before any 3.x stable tag. The embedded Deno binary in 3.2.0 will likely gain more deploy scripting APIs once the networking layer stabilizes.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Helm or werf.
MISP 2.5.46 delivers a 50× sightings query speedup and systematic SSRF closure — serious infrastructure work.
Knock plants its flag across every major AI platform: Claude, ChatGPT, Codex, and Cursor all get native connectors
Honeybadger pivots from error tracker to full observability layer with AI-native query and anomaly detection
Resend expands from email API to full platform with SSO, analytics, and AI-native dev tooling
Authelia patches two access control bypass paths from canonicalization gaps.
Quay ships a series of SSRF fixes in mirroring and proxy cache alongside steady CVE patching across 3.10 and 3.12 branches.
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — kubernetes — within Infra & APIs. Helm and werf are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Helm and werf are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Helm alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Helm alternatives" section above for the current picks, or visit /alternatives/helm for the full list with editorial commentary on each.
Top werf alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "werf alternatives" section above for the current picks, or visit /alternatives/werf for the full list with editorial commentary on each.