Ethico
The whistleblower hotline vendor is assembling a compliance suite, one module at a time.
A side-by-side editorial comparison of Shiori and Rocket.Chat — release velocity, themes, recent moves, and the top alternatives to consider.
A Go bookmark manager rebuilding itself around an API — and only ever shipping release candidates.
Shiori is a self-hosted read-later and bookmark tool whose recent history is entirely release candidates: v1.7.0-rc.2, rc.3, v1.7.2-rc.1, v1.8.0-rc.1. The visible work has moved off the web UI and into an API v1 surface — tag endpoints, bookmark-tag association, filtering and counts — plus infrastructure like proxy-header authentication and SQLite performance. The last tagged release in this window is from July 2025.
A long RC train of dependency bumps, with the real work landing in the 8.7 branch opener.
Rocket.Chat publishes every release candidate, and the shape is consistent: the .rc.0 that opens a minor carries the substance, and every RC after it is a Meteor version bump with the occasional fix. The 8.7 line opened with server-side OAuth, PKCE and state validation under a phishing-resistant MFA banner, plus session identification in device management. The four RCs since have added one user-visible fix — seekable audio attachments.
Shiori is a self-hosted read-later and bookmark tool whose recent history is entirely release candidates: v1.7.0-rc.2, rc.3, v1.7.2-rc.1, v1.8.0-rc.1. The visible work has moved off the web UI and into an API v1 surface — tag endpoints, bookmark-tag association, filtering and counts — plus infrastructure like proxy-header authentication and SQLite performance. The last tagged release in this window is from July 2025.
The project is converting from a web app with an API bolted on into an API-first service with a client, and the login component, PWA and theme work are being rewritten around that split. Proxy forward-header authentication in particular is a deployment-shape decision: it assumes Shiori sits behind an authenticating reverse proxy rather than owning identity itself. The RC-only tagging pattern makes it hard to tell what the maintainers consider stable.
The next step is presumably a final v1.8.0 consolidating the API v1 tag work, though nothing in these entries indicates the RC-to-stable promotion is scheduled. If the pattern holds, the following RC continues on API endpoints rather than the UI.
Rocket.Chat publishes every release candidate, and the shape is consistent: the .rc.0 that opens a minor carries the substance, and every RC after it is a Meteor version bump with the occasional fix. The 8.7 line opened with server-side OAuth, PKCE and state validation under a phishing-resistant MFA banner, plus session identification in device management. The four RCs since have added one user-visible fix — seekable audio attachments.
The feature direction is enterprise and regulated deployment: phishing-resistant authentication in 8.7, attribute-based access control with an external Virtru attribute store in 8.6, federation and personal-access-token correctness fixes throughout. These are the requirements of buyers who run Rocket.Chat themselves because they cannot use a hosted competitor, and the release notes read like a queue of their procurement checklists.
Expect 8.7 to reach general availability with the OAuth rework as its headline and little added beyond it, since the RC train has been quiet since rc.0. The unified presence engine whose backend landed in 8.6 has no user-facing surface yet, making it the likeliest candidate for the next minor.
Other Collab products tracked by Sparkpulse, ranked by recent ship velocity. Each card links to a full editorial trajectory and lets you pivot into a head-to-head comparison with either Shiori or Rocket.Chat.
The whistleblower hotline vendor is assembling a compliance suite, one module at a time.
Contract automation grows up: admin permission maps, 2FA, and forms that do their own arithmetic.
The knowledge graph quietly turned itself into a meetings product.
A minimal RSS reader that made passkeys the only way in, then went back to polishing the reading experience.
A self-hosted reading server that spent two releases becoming infrastructure, then paid for it with a CVE.
FreshRSS keeps turning a reader into a queryable archive — and hardening the parts that touch the web.
See all Shiori alternatives → · See all Rocket.Chat alternatives →
Latest ship moves from both products, interleaved chronologically. ⚡ = editorial spark.
Both compete on the same themes — self-hosted, release-candidates — within Collab. Rocket.Chat is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. See the at-a-glance table above for a side-by-side breakdown of velocity, recent sparks, and editorial themes.
Sparkpulse doesn't pick a winner — we score release velocity, not feature parity. Rocket.Chat is currently shipping more aggressively (velocity 6.3 vs 0.0), with 1 editorial sparks in the last 30 days against 0. For your specific use case, the alternatives sections above list other Collab products to evaluate alongside.
Top Shiori alternatives in Collab are ranked by recent ship velocity. Browse the "Shiori alternatives" section above for the current picks, or visit /alternatives/shiori for the full list with editorial commentary on each.
Top Rocket.Chat alternatives in Collab are ranked by recent ship velocity. Browse the "Rocket.Chat alternatives" section above for the current picks, or visit /alternatives/rocket-chat for the full list with editorial commentary on each.