Skipper
Skipper trims a 4x memory regression out of routesrv, days after shipping h2c
A side-by-side editorial comparison of Pacemaker and Verdaccio — release velocity, themes, recent moves, and the top alternatives to consider.
Pacemaker is putting TLS and X509 auth between its cluster nodes, then hardening the wire code.
Two branches ship in parallel: the 3.0.x line carrying new work and 2.1.x taking backported fixes. The 3.0 series added TLS for Pacemaker Remote nodes, X509 authentication, TLS certificates for remote CIB operations, and then PSK authentication for those same operations, alongside large-IPC and multipart message support. The most recent releases on both branches are the same security train, fixing CVE-2026-10649 and a set of integer overflows and size checks in the remote message code.
Verdaccio's 7.0 line is subtraction — forks dropped, toolchain swapped, tags mostly empty
The next-7 prerelease line is short and almost entirely maintenance. Its one substantive release adopted @verdaccio/server and deleted the local api, web, and storage forks, leaving a thin Storage wrapper behind only to keep callback-based storage plugins working. Everything since has been dependency retargeting, a lint and format toolchain swap, and a tag whose body reads 'chore: trigger release'.
Two branches ship in parallel: the 3.0.x line carrying new work and 2.1.x taking backported fixes. The 3.0 series added TLS for Pacemaker Remote nodes, X509 authentication, TLS certificates for remote CIB operations, and then PSK authentication for those same operations, alongside large-IPC and multipart message support. The most recent releases on both branches are the same security train, fixing CVE-2026-10649 and a set of integer overflows and size checks in the remote message code.
The cluster's internal transport is being rebuilt on the assumption that the network between nodes is not trusted. Authentication and encryption arrived first, and the fixes that followed, overflow guards and a maximum remote message size, are the hardening pass on the same code paths. Release discipline is heavy and visible: each version ships a release candidate with an identical commit set days earlier, and every 3.0 release documents the regressions it introduced and where they were fixed.
Remote CIB operations now support both X509 certificates and PSK, and the recent fixes all sit in message framing and size limits; further work is most likely to continue in that message-handling code rather than adding another authentication mechanism.
The next-7 prerelease line is short and almost entirely maintenance. Its one substantive release adopted @verdaccio/server and deleted the local api, web, and storage forks, leaving a thin Storage wrapper behind only to keep callback-based storage plugins working. Everything since has been dependency retargeting, a lint and format toolchain swap, and a tag whose body reads 'chore: trigger release'.
This is consolidation ahead of a major: the project is collapsing code it had been carrying in-tree back onto shared packages and standardising tooling around oxlint and oxfmt. The remaining compatibility shim is the visible unfinished business — it exists purely for legacy plugins, and it is the last thing standing between this line and a clean server dependency.
Removing the legacy storage wrapper is the decision this line is heading toward, and it breaks callback-based storage plugins when it lands, so expect it to arrive with the 7.0.0 final rather than in another next tag. Until then the prerelease stream will keep producing tags with no user-visible content.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Pacemaker or Verdaccio.
Skipper trims a 4x memory regression out of routesrv, days after shipping h2c
CloudStack ships two LTS branches in lockstep and publishes nothing but pointers
Kinsta is moving MyKinsta's controls into its API, one surface per month
Observability lands on OpenTelemetry semconv in the LTS train
Canvas agents gain memory, and onboarding moves into the editor
Security and governance controls catch up to the Copilot build-out
See all Pacemaker alternatives → · See all Verdaccio alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. Pacemaker is currently shipping more aggressively (velocity 6.3 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Pacemaker is currently shipping more aggressively (velocity 6.3 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top Pacemaker alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Pacemaker alternatives" section above for the current picks, or visit /alternatives/pacemaker for the full list with editorial commentary on each.
Top Verdaccio alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Verdaccio alternatives" section above for the current picks, or visit /alternatives/verdaccio for the full list with editorial commentary on each.