WorkOS
WorkOS is making agents first-class principals and taking custody of the tokens they act with.
A side-by-side editorial comparison of Infisical and ClamAV — release velocity, themes, recent moves, and the top alternatives to consider.
Infisical is growing past secrets management into PAM, PKI and an agent credential proxy.
Infisical ships a fast GitHub release train — six versions in two weeks, each bundling dozens of merged PRs. The work splits cleanly into four product lines that no longer look like one: core secrets management, a privileged access manager gaining account types, a certificate authority stack, and an agent proxy that brokers credentials to services on a caller's behalf. A parallel UI migration is moving settings screens onto v3 components, and a caching pass has pushed trusted-IP allowlists, KMS material and org membership into Redis.
Eight CVEs in one August batch — ClamAV's parser surface is the whole story.
ClamAV runs two supported lines, 1.5.x and 1.4.x, and publishes near-identical patch releases seconds apart whenever vulnerabilities land. The August pair is the largest yet in this window: eight CVEs in 1.5.4, six of them backported to 1.4.6, spanning the ZIP catalogue, GPT partition, PESpin, PDF, Mach-O and XAR parsers. Several reach back a decade or more — the PESpin overflow affects builds from 0.90 onward.
Infisical ships a fast GitHub release train — six versions in two weeks, each bundling dozens of merged PRs. The work splits cleanly into four product lines that no longer look like one: core secrets management, a privileged access manager gaining account types, a certificate authority stack, and an agent proxy that brokers credentials to services on a caller's behalf. A parallel UI migration is moving settings screens onto v3 components, and a caching pass has pushed trusted-IP allowlists, KMS material and org membership into Redis.
Each of the four lines is widening by connector rather than by rearchitecture: PAM picked up Redis accounts with browser access and connection tests across the remaining account types; rotation now covers Azure app credentials, LDAP, and Cloudflare API tokens and R2 keys; PKI added SCEP for Microsoft Intune and ADCS validation for external authorities. The agent proxy is the line to watch — it gained per-service last-used timestamps, adoption telemetry, a Google Workspace template, and the ability for user tokens to report proxied-service usage, which is the instrumentation you build before you price something. Machine identity is being hardened in parallel with expiry alerts and policy-template creation flows.
The adoption telemetry and last-used tracking around proxied services point to the agent proxy being packaged as its own thing; expect more prebuilt service templates alongside it.
ClamAV runs two supported lines, 1.5.x and 1.4.x, and publishes near-identical patch releases seconds apart whenever vulnerabilities land. The August pair is the largest yet in this window: eight CVEs in 1.5.4, six of them backported to 1.4.6, spanning the ZIP catalogue, GPT partition, PESpin, PDF, Mach-O and XAR parsers. Several reach back a decade or more — the PESpin overflow affects builds from 0.90 onward.
Feature work has been paused since 1.5.0 last October; everything since is patch traffic against the file format parsers, and the batches are growing rather than shrinking. The August release widens the surface beyond parsing for the first time here, with a clamd STATS thread-safety bug that could disclose process memory or crash the daemon. Reporter credits increasingly come from automated discovery — Atuin, GitHub Security Lab, Trail of Bits — which suggests the find rate tracks the tooling pointed at this codebase, not new code being written.
Expect the dual-branch pattern to continue and per-batch CVE counts to stay high while automated fuzzing keeps sweeping the parser surface. These entries give no indication of a 1.6 line opening — there has been no development release since the 1.5.0 cycle.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Infisical or ClamAV.
WorkOS is making agents first-class principals and taking custody of the tokens they act with.
Render swaps static keys for federated identity and opens its control plane to coding agents.
Tailnets become API-provisioned resources while Tailscale hardens SSH and thins the control plane.
Retool is turning its app builder into a branched, multi-threaded agent workspace.
Resend is turning an email API into something other people build products on.
Render is quietly becoming the credential broker between your services and AI providers.
See all Infisical alternatives → · See all ClamAV alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Infisical and ClamAV are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Infisical and ClamAV are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Infisical alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Infisical alternatives" section above for the current picks, or visit /alternatives/infisical for the full list with editorial commentary on each.
Top ClamAV alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "ClamAV alternatives" section above for the current picks, or visit /alternatives/clamav for the full list with editorial commentary on each.