← Back to home
Comparison · Infra & APIs

runc vs Heroku

A side-by-side editorial comparison of runc and Heroku — release velocity, themes, recent moves, and the top alternatives to consider.

runc vs Heroku: at a glance

FeatureruncHeroku
SectorInfra & APIsDevOps, Infra & APIs
Velocity score2.55.0
Sparks · 30d00
Top themescontainer runtime, support policy, cve coordination, multi-branchmanaged postgres, runtime upkeep, deprecation cadence, buildpacks
Last editorial update2h ago2h ago
WebsiteVisit →Visit →

What is runc?

runc now publishes an end-of-life calendar, and three branches shipped the same CVE fix in two days.

1.5.0 in June was the first stable release of the 1.5.z series and the third under runc's formal release and support policy: 1.2.z and earlier are unsupported, 1.3.z receives only high-severity CVE fixes until the end of October 2026, and 1.4.z is limited to security and significant bugfixes. A month later 1.5.1 fixed a real-world regression — the maskPaths optimisation from 1.5.0-rc.3 broke tmpfs mounts with nr_inodes=1 on Ubuntu 20.04 kernels. In mid-June, CVE-2026-41579 was fixed simultaneously across 1.3.6, 1.4.3 and 1.5.0-rc.3 and released with no embargo.

Read the full runc trajectory →

What is Heroku?

Runtime bumps fill the changelog; the managed Postgres line is where Heroku actually moves.

Day to day, Heroku's changelog is language-runtime upkeep: Python, Node, Ruby, Go, PHP, JRuby and .NET point releases, buildpack refreshes for Pipenv and uv, and periodic rebuilds of the Heroku-22, Heroku-24 and Heroku-26 stacks now maintained in parallel. The exception is the managed database. Postgres 18 entered beta on 14 July and reached general availability on 4 August, and Heroku deprecated Postgres 15 on the same day.

Read the full Heroku trajectory →

runc vs Heroku: editorial side-by-side

R
runc
INFRA · APIS
2.5

runc now publishes an end-of-life calendar, and three branches shipped the same CVE fix in two days.

◆ Current state

1.5.0 in June was the first stable release of the 1.5.z series and the third under runc's formal release and support policy: 1.2.z and earlier are unsupported, 1.3.z receives only high-severity CVE fixes until the end of October 2026, and 1.4.z is limited to security and significant bugfixes. A month later 1.5.1 fixed a real-world regression — the maskPaths optimisation from 1.5.0-rc.3 broke tmpfs mounts with nr_inodes=1 on Ubuntu 20.04 kernels. In mid-June, CVE-2026-41579 was fixed simultaneously across 1.3.6, 1.4.3 and 1.5.0-rc.3 and released with no embargo.

◆ Where it's heading

The project is behaving like infrastructure with a contract. Publishing dated support windows and shipping a coordinated fix across every live branch on the same day is the operating posture of a component that sits under every container on a host, where operators need to know what they are still entitled to. The CVE itself is instructive: a /dev symlink escape in the same family as three earlier CVEs, found by re-auditing the rootfs preparation code that had been hardened before.

◆ Prediction

1.5.0's notes state that a 1.6.0 is expected in late October 2026, which is also when 1.3.z support ends — so the next milestone is that pairing. Expect 1.5.z patches until then.

Heroku logo
Heroku
DEVOPSINFRA · APIS
5.0

Runtime bumps fill the changelog; the managed Postgres line is where Heroku actually moves.

◆ Current state

Day to day, Heroku's changelog is language-runtime upkeep: Python, Node, Ruby, Go, PHP, JRuby and .NET point releases, buildpack refreshes for Pipenv and uv, and periodic rebuilds of the Heroku-22, Heroku-24 and Heroku-26 stacks now maintained in parallel. The exception is the managed database. Postgres 18 entered beta on 14 July and reached general availability on 4 August, and Heroku deprecated Postgres 15 on the same day.

◆ Where it's heading

The platform is running two clocks at once. One is a near-daily maintenance cadence that keeps supported runtimes current and rarely changes behaviour. The other is a deliberate, publicly staged lifecycle for the data services, where a major version is walked from beta to GA and the version three releases behind is retired in the same announcement. Kafka is on the same track, with 2.8 and 3.7 deprecations and a revised version-support policy posted in late July.

◆ Prediction

Given that Postgres 15's deprecation was announced alongside 18's general availability, the next concrete step is a published end-of-life date and forced-upgrade window for Postgres 15. The runtime bumps will continue at their current weekly rhythm.

runc alternatives

Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Tap any card for the full editorial trajectory or compare directly with runc.

See all runc alternatives →

Heroku alternatives

Other Infra & APIs products tracked by Sparkpulse, ranked by recent ship velocity. Tap any card for the full editorial trajectory or compare directly with Heroku.

See all Heroku alternatives →

Recent activity from runc and Heroku

Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.

  1. 1d agoHerokuPostgres 18 GA and Postgres 15 deprecation; Python 3.14.7 and 3.13.15
  2. 23d agoHeroku.NET SDK updates across the 8.0, 9.0 and 10.0 lines
  3. 24d agoHerokuPostgres 18 enters beta; sbt 2 supported for Scala apps
  4. 24d agorunctmpfs regression on Ubuntu 20.04 kernels fixed
  5. 25d agoHerokuHeroku-22, Heroku-24 and Heroku-26 stacks updated
  6. 28d agoHerokuPython buildpacks updated to Pipenv 2026.6.2 and uv 0.11.28
  7. 29d agoHerokuNode.js 26.5.0 now available
  8. 1mo agoruncrunc 1.5.0 stable, with dated support windows for older branches
  9. 1mo agoruncCVE-2026-41579: /dev symlink host write access fixed
  10. 1mo agoruncRelease candidate carrying the CVE-2026-41579 fix
  11. 1mo agoruncCVE-2026-41579 fix backported to the 1.4 branch
  12. 4mo agoruncBuild fixes and seccomp WaitKillableRecv support

Frequently asked questions

What is the difference between runc and Heroku?

They serve adjacent needs but don't currently overlap on shipped themes. Heroku is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.

Is runc better than Heroku?

Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Heroku is currently shipping more aggressively (velocity 5.0 vs 2.5), with 0 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Infra & APIs products to evaluate alongside.

What are the best alternatives to runc?

Top runc alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "runc alternatives" section above for the current picks, or visit /alternatives/runc for the full list with editorial commentary on each.

What are the best alternatives to Heroku?

Top Heroku alternatives in Infra & APIs are ranked by recent ship velocity. Browse the "Heroku alternatives" section above for the current picks, or visit /alternatives/heroku for the full list with editorial commentary on each.