Kinsta
Kinsta is moving MyKinsta's control panel into its API, one surface at a time.
A side-by-side editorial comparison of PocketBase and authentik — release velocity, themes, recent moves, and the top alternatives to consider.
Two maintained branches, a paired-release rhythm, and a window with no new features in it.
PocketBase runs two branches in lockstep: v0.39.x current and v0.22.x, which receives an explicitly labeled backport within minutes of nearly every 0.39 patch. That doubles the apparent release count — the last four calendar dates in this window each produced two tags carrying the same change. The content is uniformly maintenance: JSVM and goja regressions, filter-expression handling, SQLite bumps, and small admin-UI fixes.
Two supported branches, every release a bot-driven cherry-pick — authentik is in pure maintenance here
All six releases in this window are patches across two maintained branches, 2026.5.x and 2026.2.x, and nearly every commit in them is a cherry-pick bot backporting a fix from main. The content is fixes and documentation rather than capability: reverting locale-driven flow re-requests in the flow executor, handling an exception in connector controller sync setup, fixing outgoing sync discovery running once per page, migrating OpenID conformance tests to upstream images, and additional SCIM provider documentation. The one change with an operational edge is 2026.5.6 dropping curl and runit from the container image.
PocketBase runs two branches in lockstep: v0.39.x current and v0.22.x, which receives an explicitly labeled backport within minutes of nearly every 0.39 patch. That doubles the apparent release count — the last four calendar dates in this window each produced two tags carrying the same change. The content is uniformly maintenance: JSVM and goja regressions, filter-expression handling, SQLite bumps, and small admin-UI fixes.
The recent through-line is supply-chain and runtime caution rather than feature work. v0.39.7 forked ozzo-validation after the upstream library changed ownership, with a stated intent to eventually replace it entirely, and shipped a fix for an unhandled panic in worker goroutines. v0.39.10 then reverts the CLI's automatic panic recovery to restore non-zero exit codes, deferring proper exit-code support to v0.40 or v0.41 — the only forward-looking commitment anywhere in this window.
The 0.39.x line looks like it is being held stable while v0.40/v0.41 absorbs the CLI exit-code rework, so expect continued paired patch pairs with dependency bumps until that branch opens.
All six releases in this window are patches across two maintained branches, 2026.5.x and 2026.2.x, and nearly every commit in them is a cherry-pick bot backporting a fix from main. The content is fixes and documentation rather than capability: reverting locale-driven flow re-requests in the flow executor, handling an exception in connector controller sync setup, fixing outgoing sync discovery running once per page, migrating OpenID conformance tests to upstream images, and additional SCIM provider documentation. The one change with an operational edge is 2026.5.6 dropping curl and runit from the container image.
The release pattern says more than the contents: two branches maintained in parallel with the same fixes landing on each — 2026.2.6 and 2026.5.5 shipped the same day carrying the same conformance-test migration — which is the shape of a project supporting long-lived deployments rather than pushing users forward. Feature work is happening on main and is not visible in this feed; what reaches these branches is the fix subset. Removing curl and runit from the image continues a slow trimming of what ships inside the container.
The visible pattern supports only more of the same: alternating 2026.5.x and 2026.2.x patches assembled from cherry-picks, until a new feature branch is cut. Nothing in these entries indicates what that branch will contain.
Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either PocketBase or authentik.
Kinsta is moving MyKinsta's control panel into its API, one surface at a time.
GitHub killed its model-hosting product and shipped stacked PRs in the same week.
Ably is building an agent transport layer, shipping a new AI SDK version roughly every ten days.
One commit per release, and most of them are closing security holes in the Cloud Code and query paths.
Three branches patched in lockstep for an unauthenticated takeover — then patched again for the fix's regression.
Three branches tagged on one day, with the actual release notes published somewhere else
See all PocketBase alternatives → · See all authentik alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
They serve adjacent needs but don't currently overlap on shipped themes. PocketBase and authentik are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. PocketBase and authentik are shipping at a similar cadence (velocity 5.0 vs 5.0, both within Sparkpulse's "active" band). For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.
Top PocketBase alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "PocketBase alternatives" section above for the current picks, or visit /alternatives/pocketbase for the full list with editorial commentary on each.
Top authentik alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "authentik alternatives" section above for the current picks, or visit /alternatives/authentik for the full list with editorial commentary on each.