Skipper
Skipper fixes two silent data-loss bugs — body truncation on large requests and multi-value header drops.
A side-by-side editorial comparison of Nebula and ToolJet — release velocity, themes, recent moves, and the top alternatives to consider.
Nebula closes a firewall bypass that let unparsed IPv6 protocols match TCP rules
Nebula is a peer-to-peer mesh VPN built around a certificate authority model. v1.10.0 was the pivot — IPv6 and multiple addresses in the overlay, plus a v2 ASN.1 certificate format with a unified interface for external implementations — and everything since has been consequence management. v1.11.0 shifted to the operational surface with structured slog logging, corrected firewall reject-versus-drop semantics, and Windows WFP filters by default. v1.11.1 returns to the packet classifier: IPv6 packets whose next header Nebula does not parse were being misread as TCP or UDP and matched against TCP/UDP firewall rules, and are now classified as their true protocol with no ports.
ToolJet ships Custom Component Library and tightens enterprise controls on path to AI-native low-code.
ToolJet is running two parallel tracks: an LTS branch delivering incremental reliability and plan-level limit expansions, and a beta track already carrying LLM provider switching, MCP bundled into the EE image, Personal Access Tokens, and 2FA. The gap between beta and stable is where the platform's real direction lives — AI builder + enterprise security controls converging into a single product.
Nebula is a peer-to-peer mesh VPN built around a certificate authority model. v1.10.0 was the pivot — IPv6 and multiple addresses in the overlay, plus a v2 ASN.1 certificate format with a unified interface for external implementations — and everything since has been consequence management. v1.11.0 shifted to the operational surface with structured slog logging, corrected firewall reject-versus-drop semantics, and Windows WFP filters by default. v1.11.1 returns to the packet classifier: IPv6 packets whose next header Nebula does not parse were being misread as TCP or UDP and matched against TCP/UDP firewall rules, and are now classified as their true protocol with no ports.
The security findings since v1.10.0 map onto the same seam — the IPv6 support that release added widened what the classifier and the certificate validator have to handle, and each subsequent release has closed another gap in that widened surface. v1.11.1 is notable for making the fix a deliberate operational break: carrying SCTP, GRE or IP-in-IP over the overlay may have been working only through the bypass, so operators must add a proto: any rule before upgrading. That the project chose correct classification over compatibility, and said so plainly in the notes, is consistent with how the firewall direction fix was handled one release earlier.
The stated plan to assert low-s signature form when validating certificates remains the concrete next step visible in these entries; expect it as a breaking validation change. The classifier work suggests remaining IPv6 extension-header handling is the other likely source of findings.
ToolJet is running two parallel tracks: an LTS branch delivering incremental reliability and plan-level limit expansions, and a beta track already carrying LLM provider switching, MCP bundled into the EE image, Personal Access Tokens, and 2FA. The gap between beta and stable is where the platform's real direction lives — AI builder + enterprise security controls converging into a single product.
The consolidation of tooljet-mcp into the EE production image is the clearest signal: ToolJet is treating MCP as a first-class integration layer, not an experiment. PATs threading through groups, workflows, plugins, and MCP auth suggest an API-first model is being built on top of the visual layer. The Custom Component Library core gives power users the extensibility path that previously required forking the platform.
LLM provider switching and MCP-based datasource connectivity will stabilize to LTS within the next few releases — both are already merged in EE. Once stable, these features position ToolJet against agentic-workflow tools as much as against no-code competitors.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Nebula or ToolJet.
Skipper fixes two silent data-loss bugs — body truncation on large requests and multi-value header drops.
GitHub turns Copilot into an org-wide default, adds memory to agentic security fixes.
werf's v3 dev track ships multi-namespace cleanup scanning and JSON config schemas in rapid succession
Buildkite ships a caching product with cache-poisoning controls baked in as it builds toward AI-agent-operated CI.
Jackett ships daily tracker maintenance — domain fixes, new indexers, no architectural movement.
Tailscale launches PAM beta, staking out privileged access alongside its AI gateway
See all Nebula alternatives → · See all ToolJet alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. ToolJet is currently shipping more aggressively (velocity 6.3 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. ToolJet is currently shipping more aggressively (velocity 6.3 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Nebula alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Nebula alternatives" section above for the current picks, or visit /alternatives/nebula-networking for the full list with editorial commentary on each.
Top ToolJet alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "ToolJet alternatives" section above for the current picks, or visit /alternatives/tooljet for the full list with editorial commentary on each.