Ethico
The whistleblower hotline vendor is assembling a compliance suite, one module at a time.
A side-by-side editorial comparison of Miniflux and Paperless-ngx — release velocity, themes, recent moves, and the top alternatives to consider.
A minimal RSS reader that made passkeys the only way in, then went back to polishing the reading experience.
Miniflux ships a release roughly monthly, and the 2.2.19-through-2.3.1 stretch was almost entirely security work: OIDC token signature verification, PKCE state cleanup, SHA1 replaced with HMAC-SHA256 for Google Reader API auth, an OAuth account-binding vulnerability, an open redirect, and a possible SQL injection in dynamically built ORDER BY clauses. The two most recent releases return to product — full-text search on PostgreSQL's websearch_to_tsquery, an expanded API v1, and feed language detection.
Paperless-ngx shipped its 3.0 rewrite, then spent a week putting out the fires.
3.0.0 landed on July 22 after a long beta, carrying both the largest feature set in the project's history and nine breaking changes. The five releases since are pure repair: a broken migration in 3.0.1 that forced an immediate 3.0.2, then three patch rounds covering OCR skipping, permission-filtered dedup, Gotenberg conversion, email date parsing, AI suggestion caching and search index edge cases. The pace tells you 3.0 shipped into real deployments fast.
Miniflux ships a release roughly monthly, and the 2.2.19-through-2.3.1 stretch was almost entirely security work: OIDC token signature verification, PKCE state cleanup, SHA1 replaced with HMAC-SHA256 for Google Reader API auth, an OAuth account-binding vulnerability, an open redirect, and a possible SQL injection in dynamically built ORDER BY clauses. The two most recent releases return to product — full-text search on PostgreSQL's websearch_to_tsquery, an expanded API v1, and feed language detection.
Two threads run in parallel. The security thread has systematically closed off every authentication path that was not cryptographically strict, culminating in 2.3.0 restricting WebAuthn login to discoverable passkeys only. The product thread is API-shaped: entry ID pagination, bulk starred updates, tag filtering, and a Go client that now exposes the full feed record — all aimed at people driving Miniflux from other software rather than its own UI.
The API surface is the area with visible momentum, so the next release most likely extends filtering or bulk operations further. Whether the passkey-only stance loosens to accommodate post-password MFA is the open question these notes raise but do not answer.
3.0.0 landed on July 22 after a long beta, carrying both the largest feature set in the project's history and nine breaking changes. The five releases since are pure repair: a broken migration in 3.0.1 that forced an immediate 3.0.2, then three patch rounds covering OCR skipping, permission-filtered dedup, Gotenberg conversion, email date parsing, AI suggestion caching and search index edge cases. The pace tells you 3.0 shipped into real deployments fast.
The project has moved from a document scanner-and-tagger to a document platform with AI in the core: Paperless AI, remote OCR via Azure, a document parser plugin framework, tantivy replacing Whoosh for search, file versions and sharelink bundles. The breaking changes are the other half of that story — dropping API v1, Python 3.10, document encryption and the old consumer clears the decks for that platform. Recent patches keep touching LLM plumbing, including passing output language into chat and adding docstrings so the classifier reads better as an LLM tool.
The 3.0.x patch cadence looks set to run at least another round or two — 3.0.5 is still landing search-compatibility and AI-suggestion fixes rather than tapering. Feature work resuming before that queue empties would be the surprise.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Miniflux or Paperless-ngx.
The whistleblower hotline vendor is assembling a compliance suite, one module at a time.
Contract automation grows up: admin permission maps, 2FA, and forms that do their own arithmetic.
The knowledge graph quietly turned itself into a meetings product.
A Go bookmark manager rebuilding itself around an API — and only ever shipping release candidates.
A self-hosted reading server that spent two releases becoming infrastructure, then paid for it with a CVE.
FreshRSS keeps turning a reader into a queryable archive — and hardening the parts that touch the web.
See all Miniflux alternatives → · See all Paperless-ngx alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted — within Collab. Paperless-ngx is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Paperless-ngx is currently shipping more aggressively (velocity 6.3 vs 2.5), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top Miniflux alternatives in Collab are ranked by recent ship velocity. Browse the "Miniflux alternatives" section above for the current picks, or visit /alternatives/miniflux for the full list with editorial commentary on each.
Top Paperless-ngx alternatives in Collab are ranked by recent ship velocity. Browse the "Paperless-ngx alternatives" section above for the current picks, or visit /alternatives/paperless-ngx for the full list with editorial commentary on each.